CVE-2020-25657 describes a Bleichenbacher timing attack vulnerability in all released versions of m2crypto, impacting products like fedoraproject and redhat. This flaw allows an attacker to potentially decrypt RSA ciphertext by observing timing differences during processing. With a CVSS score of 5.9 (MEDIUM), it poses a high threat to confidentiality due to its network-based attack vector and high attack complexity. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing exists, the vulnerability has garnered some community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:m2crypto_project:m2crypto:*:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2020-25657
Jun 11, 2024A flaw was found in all released versions of m2crypto where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.
Jan 12, 2021m2crypto: bleichenbacher timing attacks in the RSA decryption API
Nov 13, 2020