CVE-2018-16868 is a Bleichenbacher type side-channel vulnerability affecting GNU GnuTLS, specifically in its handling of RSA decrypted PKCS#1 v1.5 data. An attacker with local access to the same physical core as the victim process could exploit this to extract plaintext or downgrade TLS connections. Rated Medium (CVSS 5.6), this attack requires physical proximity and high attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.6.4CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.