Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-0169

36
FAUCET Score

CVE-2013-0169, known as "Lucky Thirteen," is a timing side-channel vulnerability affecting TLS 1.1/1.2 and DTLS 1.0/1.2 implementations in products like OpenSSL, OpenJDK, and PolarSSL. It allows remote attackers to perform plaintext-recovery attacks by analyzing timing differences during the processing of malformed CBC padding. The vulnerability has a CVSS score of 2.6 (low severity), indicating a network attack vector with high attack complexity and a partial impact on confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.9.8, <= 0.9.8xCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 1.0.0, <= 1.0.0jCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 1.0.1, <= 1.0.1dCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
1.6.0CPE matchmatch criteria
cpe:2.3:a:oracle:openjdk:1.6.0:-:*:*:*:*:*:*
1.6.0CPE matchmatch criteria
cpe:2.3:a:oracle:openjdk:1.6.0:update1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

2.6LOW

AV:N/AC:H/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
4.9
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
35.58%
Probability of exploitation in next 30 days
EPSS Percentile
98.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.3558 is in the 99th percentile among its peer group of 1,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (30)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: java-1.6.0-openjdk-1:1.6.0.0-1.35.1.11.8.el5_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: java-1.7.0-openjdk-1:1.7.0.9-2.3.7.1.el5_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: openssl-0:0.9.8e-26.el5_9.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: java-1.6.0-openjdk-1:1.6.0.0-1.56.1.11.8.el6_3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: java-1.7.0-openjdk-1:1.7.0.9-2.3.7.1.el6_3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openssl-0:1.0.0-27.el6_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 5.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6.1Fixed in: openssl
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Platform 5.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 2.0Fixed in: openssl
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.4Fixed in: java-1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el5_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.5Fixed in: java-1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el5_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.6Fixed in: openshift4/ose-kube-rbac-proxy:v4.6.0-202010061132.p0
View patch
redhatpatch availablevia redhat_api
Product: RHEV 3.X Hypervisor and Agents for RHEL-6Fixed in: rhev-hypervisor6-0:6.4-20130306.2.el6_4
View patch
redhatpatch availablevia redhat_api
Product: RHEV Manager version 3.3Fixed in: spice-client-msi-0:3.3-12
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.6.0-sun-1:1.6.0.41-1jpp.1.el5_9
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.7.0-oracle-1:1.7.0.15-1jpp.1.el5_9
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.7.0-ibm-1:1.7.0.4.2-1jpp.1.el5_9
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.6.0-ibm-1:1.6.0.13.2-1jpp.1.el5_9
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.5.0-ibm-1:1.5.0.16.2-1jpp.1.el5_9
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: java-1.6.0-sun-1:1.6.0.41-1jpp.1.el6_3
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: java-1.7.0-oracle-1:1.7.0.15-1jpp.1.el6_3
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: java-1.7.0-ibm-1:1.7.0.4.2-1jpp.1.el6_4
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: java-1.6.0-ibm-1:1.6.0.13.2-1jpp.1.el6_4
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: java-1.5.0-ibm-1:1.5.0.16.2-1jpp.1.el6_4
View patch
wagopatch availablevia llm_extracted
Fixed in: ['7.2.3', '8.0.3']
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: openssl097a
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openssl098e
redhatend of lifevia redhat_api
Product: Red Hat JBoss Enterprise Web Server 1Fixed in: openssl
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: haproxy

Vendor Advisories (2)

redhatCVE-2013-0169Moderate

SSL/TLS: CBC padding timing attack (lucky-13)

Feb 4, 2013
wagollm-wago-974549d5a3bd6628LOW

Upgrade to JDK 1.6 u41 Upgrade OpenSSL to 1.0.0k Upgrade to JDK 1.7u15+ Upgrade to OpenSSL 1.0.1d

References

blog.fuseyism.com / index.php/2013/02/20/security-icedtea-2-1-6-2-2-6-2-3-7-for-openjdk-7-released
Third Party Advisory
lists.apple.com / archives/security-announce/2013/Sep/msg00002.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2013-April/101366.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2013-02/msg00020.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2013-03/msg00000.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2013-03/msg00002.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2013-04/msg00020.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-03/msg00001.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-03/msg00027.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-03/msg00011.html
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
openwall.com / lists/oss-security/2013/02/05/24
Mailing List
rhn.redhat.com / errata/RHSA-2013-0587.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2013-0782.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2013-0783.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2013-0833.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2013-1455.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2013-1456.html
Third Party Advisory
cert-portal.siemens.com / productcert/pdf/ssa-556833.pdf
Third Party Advisory
secunia.com / advisories/53623
Third Party Advisory
secunia.com / advisories/55108
Third Party Advisory
secunia.com / advisories/55139
Third Party Advisory
secunia.com / advisories/55322
Third Party Advisory
secunia.com / advisories/55350
Third Party Advisory
secunia.com / advisories/55351
Third Party Advisory
security.gentoo.org / glsa/glsa-201406-32.xml
Third Party Advisory
lists.debian.org / debian-lts-announce/2018/09/msg00029.html
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18841
Tool Signature
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19016
Tool Signature
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19424
Tool Signature
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19540
Tool Signature
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19608
Third Party Advisory
polarssl.org / tech-updates/releases/polarssl-1.2.5-released
Vendor Advisory
puppet.com / security/cve/cve-2013-0169
Third Party Advisory
support.hpe.com / hpsc/doc/public/display
Third Party Advisory
support.apple.com / kb/HT5880
Third Party Advisory
wiki.mageia.org / en/Support/Advisories/MGASA-2013-0084
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
debian.org / security/2013/dsa-2621
Third Party Advisory
debian.org / security/2013/dsa-2622
Third Party Advisory
isg.rhul.ac.uk / tls/TLStiming.pdf
Third Party Advisory
kb.cert.org / vuls/id/737740
Third Party AdvisoryUS Government Resource
mandriva.com / security/advisories
Third Party Advisory
matrixssl.org / news.html
Third Party Advisory
openssl.org / news/secadv_20130204.txt
Vendor Advisory
oracle.com / technetwork/topics/security/javacpufeb2013update-1905892.html
Third Party Advisory
securityfocus.com / bid/57778
Third Party AdvisoryVDB Entry
securitytracker.com / id/1029190
Third Party AdvisoryVDB Entry
splunk.com / view/SP-CAAAHXG
Third Party Advisory
ubuntu.com / usn/USN-1735-1
Third Party Advisory
us-cert.gov / cas/techalerts/TA13-051A.html
Third Party AdvisoryUS Government Resource