CVE-2017-13098, also known as "ROBOT," affects BouncyCastle TLS versions prior to 1.0.3 when configured to use JCE for cryptographic functions. This vulnerability presents a weak Bleichenbacher oracle when any TLS cipher suite employing RSA key exchange is negotiated. An attacker can exploit this to recover the private key from a vulnerable application. With a CVSS score of 5.9 (Medium) and an EPSS percentile of 98.254%, this vulnerability has a high attack complexity but allows for remote exploitation without user interaction, leading to a high impact on confidentiality. While not on the KEV catalog, a Metasploit module exists for scanning, and it has garnered community discussion and media coverage, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.59CPE matchmatch criteria | cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.