Vulnerability Name: | CVE-2020-20950 (CCN-195234) | ||||||||||||
Assigned: | 2020-08-13 | ||||||||||||
Published: | 2021-01-18 | ||||||||||||
Updated: | 2021-09-08 | ||||||||||||
Summary: | Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure. | ||||||||||||
CVSS v3 Severity: | 5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-327 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MISC Type: Technical Description, Third Party Advisory http://archiv.infsec.ethz.ch/education/fs08/secsem/bleichenbacher98.pdf Source: MITRE Type: CNA CVE-2020-20950 Source: MISC Type: Product http://microchip.com Source: CCN Type: Medium Web site Silence Will Fall (Or How It Can Take 2 Years to Get Your Vuln Registered) Source: MISC Type: Technical Description, Third Party Advisory https://bi-zone.medium.com/silence-will-fall-or-how-it-can-take-2-years-to-get-your-vuln-registered-e6134846f5bb Source: XF Type: UNKNOWN microchip-cve202020950-info-disc(195234) Source: CCN Type: Microchip Web site Microchip Libraries for Applications (MLA) Source: MISC Type: Product https://www.microchip.com/mplab/microchip-libraries-for-applications | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||
BACK |