Vulnerabilities > CVE-2024-0553 - Information Exposure Through Discrepancy vulnerability in multiple products

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
gnu
fedoraproject
redhat
CWE-203

Summary

A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.

Vulnerable Configurations

Part Description Count
Application
Gnu
357
OS
Fedoraproject
1
OS
Redhat
2

Common Weakness Enumeration (CWE)

References