CVE-2018-16253 is a critical vulnerability in axTLS version 2.1.3 and earlier, specifically within the sig_verify() function in x509.c. This flaw allows remote attackers to forge PKCS#1 v1.5 signatures by exploiting improper ASN.1 metadata verification, particularly when small public exponents are in use. The vulnerability has a CVSS v3.0 score of 5.9 (Medium), indicating a network-based attack with high impact on integrity, but requiring high attack complexity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1.3CPE matchmatch criteria | cpe:2.3:a:axtls_project:axtls:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.