7.5
CVE-2023-33850
- EPSS 0.05%
- Veröffentlicht 22.08.2023 21:15:07
- Zuletzt bearbeitet 03.11.2025 22:16:22
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Txseries For Multiplatform Version8.1
Ibm ≫ Txseries For Multiplatform Version9.1
Ibm ≫ Txseries For Multiplatform Version8.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.134 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| psirt@us.ibm.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-203 Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.