5.9
CVE-2020-20950
- EPSS 0.24%
- Veröffentlicht 19.01.2021 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:12:20
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ietf ≫ Public Key Cryptography Standards #1 Version1.5
Microchip ≫ Microchip Libraries For Applications Version <= 2018-11-26
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.24% | 0.446 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.