CVE-2025-13470 is a critical vulnerability in RNP version 0.18.0 where a refactoring regression causes the symmetric session key for Public-Key Encrypted Session Key (PKESK) packets to be uninitialized, resulting in an all-zero key. This allows for trivial decryption of any data encrypted using public-key encryption in this specific RNP version, fully compromising confidentiality. The vulnerability carries a CVSS score of 7.5 (High), indicating a network-exploitable flaw with low attack complexity and high impact on confidentiality, with no impact on integrity or availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Ribose | RNP | 0.18.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:H/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.