Vulnerabilities > CVE-2005-1797 - Unspecified vulnerability in Openssl
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN openssl
nessus
Summary
The design of Advanced Encryption Standard (AES), aka Rijndael, allows remote attackers to recover AES keys via timing attacks on S-box lookups, which are difficult to perform in constant time in AES implementations.
Vulnerable Configurations
Nessus
NASL family | Web Servers |
NASL id | OPENSSL_AES_TIMING_ATTACK.NASL |
description | S-box lookup can hardly be performed in constant time in AES implementations. Theoretically, remote attackers could recover AES keys by performing a timing attack on these S-box lookup. No practical implementation of a remote attack is known. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 17769 |
published | 2012-01-04 |
reporter | This script is Copyright (C) 2012-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/17769 |
title | OpenSSL AES Timing Attack |
code |
|
Statements
contributor | Joshua Bressers |
lastmodified | 2008-07-08 |
organization | Red Hat |
statement | The OpenSSL Team do not consider this issue to be a practical threat. Conducting an attack such as this has shown to be impractical outside of a controlled lab environment. If the OpenSSL Team decide to produce an update to correct this issue, we will consider including it in a future security update. |