CVE-2026-3337 is a medium-severity timing side-channel vulnerability in AWS-LC's AES-CCM decryption, specifically impacting implementations using the EVP CIPHER API (EVP_aes_128_ccm, EVP_aes_192_ccm, and EVP_aes_256_ccm). An unauthenticated attacker can potentially determine the validity of authentication tags through timing analysis. The CVSS score is 5.9, indicating a network attack vector with high attack complexity and a high impact on integrity, though confidentiality and availability are not affected. There is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, but it has garnered some community discussion and media coverage. Customers using AWS services are not impacted, but applications directly using AWS-LC should upgrade to version 1.69.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.13.0, < 0.13.12CPE matchmatch criteria | cpe:2.3:a:amazon:aws-lc-fips-sys:*:*:*:*:*:rust:*:* | ||
>= 0.14.0, < 0.38.0CPE matchmatch criteria | cpe:2.3:a:amazon:aws-lc-sys:*:*:*:*:*:rust:*:* | ||
>= 1.21.0, < 1.69.0CPE matchmatch criteria | cpe:2.3:a:amazon:aws_libcrypto:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.2.0CPE matchmatch criteria | cpe:2.3:a:amazon:aws_libcrypto:*:*:*:*:fips:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.