5.9

CVE-2020-20949

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
St ≫ Stm32cubef0 Version -
St ≫ Stm32cubef1 Version -
St ≫ Stm32cubef2 Version -
St ≫ Stm32cubef3 Version -
St ≫ Stm32cubef4 Version -
St ≫ Stm32cubef7 Version -
St ≫ Stm32cubeg0 Version -
St ≫ Stm32cubeg4 Version -
St ≫ Stm32cubeh7 Version -
St ≫ Stm32cubeide Version -
St ≫ Stm32cubel0 Version -
St ≫ Stm32cubel1 Version -
St ≫ Stm32cubel4 Version -
St ≫ Stm32cubel5 Version -
St ≫ Stm32cubemonitor Version -
St ≫ Stm32cubemp1 Version -
St ≫ Stm32cubemx Version -
St ≫ Stm32cubeprogrammer Version -
St ≫ Stm32cubewb Version -
St ≫ Stm32cubewl Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.92% 0.555
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-327 Use of a Broken or Risky Cryptographic Algorithm

The product uses a broken or risky cryptographic algorithm or protocol.

http://archiv.infsec.ethz.ch/education/fs08/secsem/bleichenbacher98.pdf
Third Party Advisory
Technical Description
https://bi-zone.medium.com/silence-will-fall-or-how-it-can-take-2-years-to-get-your-vuln-registered-e6134846f5bb
Third Party Advisory
Technical Description
https://www.st.com/en/embedded-software/x-cube-cryptolib.html
Third Party Advisory