Vulnerabilities > CVE-2024-0202 - Information Exposure Through Discrepancy vulnerability in Cryptlib 3.4.4

047910
CVSS 5.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
high complexity
cryptlib
CWE-203

Summary

A security vulnerability has been identified in the cryptlib cryptographic library when cryptlib is compiled with the support for RSA key exchange ciphersuites in TLS (by setting the USE_RSA_SUITES define), it will be vulnerable to the timing variant of the Bleichenbacher attack. An attacker that is able to perform a large number of connections to the server will be able to decrypt RSA ciphertexts or forge signatures using server's certificate.

Vulnerable Configurations

Part Description Count
Application
Cryptlib
1

Common Weakness Enumeration (CWE)