V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2020-20949
CVE
Medium

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). …

CVSS
5.9
Medium
EPSS
0.01
p55
Published
2020-01-01
Updated
2020-01-01
Description

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.

Tags · CWE
Pre-authCrypto
CWE-327
CAPEC-20
CAPEC-97
CAPEC-459
CAPEC-473
CAPEC-475
CAPEC-608
CAPEC-614
Affected products
Public_key_cryptography_standards_\#1
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Timeline
2020-01-01
Published
2020-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.009 · p55
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-473 · CWE-327
└ via CAPEC-473 · CWE-327
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
public_key_cryptography_standards_#1*Tracked
stm32cubef0*Tracked
stm32cubef1*Tracked
stm32cubef2*Tracked
stm32cubef3*Tracked
stm32cubef4*Tracked
stm32cubef7*Tracked
stm32cubeg0*Tracked
stm32cubeg4*Tracked
stm32cubeh7*Tracked
stm32cubeide*Tracked
stm32cubel0*Tracked
stm32cubel1*Tracked
stm32cubel4*Tracked
stm32cubel4+*Tracked
stm32cubel5*Tracked
stm32cubemonitor*Tracked
stm32cubemp1*Tracked
stm32cubemx*Tracked
stm32cubeprogrammer*Tracked
Showing first 20 of 22
Source databases
CVE