Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-25657

21
FAUCET Score

CVE-2020-25657 describes a Bleichenbacher timing attack vulnerability in all released versions of m2crypto, impacting products like fedoraproject and redhat. This flaw allows an attacker to potentially decrypt RSA ciphertext by observing timing differences during processing. With a CVSS score of 5.9 (MEDIUM), it poses a high threat to confidentiality due to its network-based attack vector and high attack complexity. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing exists, the vulnerability has garnered some community discussion and media coverage, indicating awareness of its potential impact.

Impacted Technologies

VendorProductVersion(s)CPE
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:a:m2crypto_project:m2crypto:*:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
33CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.9MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.73%
Probability of exploitation in next 30 days
EPSS Percentile
75.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0173 is in the 53rd percentile among its peer group of 19,955 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 0.38.0-3
microsoftpatch availablevia msrc
Product: 19093-16823Fixed in: 0.38.0-3
microsoftpatch availablevia msrc
Product: 19094-17084Fixed in: 0.38.0-3
microsoftpatch availablevia msrc
Product: 19092-16820Fixed in: 0.35.2-8
microsoftpatch availablevia msrc
Product: 16992-17084Fixed in: 0.38.0-3
microsoftpatch availablevia msrc
Product: azl3 m2crypto 0.38.0-4 on Azure Linux 3.0Fixed in: 0.38.0-3
microsoftpatch availablevia msrc
Product: cbl2 m2crypto 0.38.0-3 on CBL Mariner 2.0Fixed in: 0.38.0-3
microsoftpatch availablevia msrc
Product: azl3 m2crypto 0.38.0-3 on Azure Linux 3.0Fixed in: 0.38.0-3
microsoftpatch availablevia msrc
Product: cm1 m2crypto 0.35.2-8 on CBL Mariner 1.0Fixed in: 0.35.2-8
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 0.38.0-3
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 0.38.0-3
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 0.38.0-3
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization Engine 4.4Fixed in: org.ovirt.engine-root-0:4.4.5.9-1
View patch

Vendor Advisories (3)

microsoft2024-Jun/CVE-2020-25657

CVE-2020-25657

Jun 11, 2024
microsoft2021-Jan/CVE-2020-25657Moderate

A flaw was found in all released versions of m2crypto where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.

Jan 12, 2021
redhatCVE-2020-25657Moderate

m2crypto: bleichenbacher timing attacks in the RSA decryption API

Nov 13, 2020

References

bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory