Vulnerabilities (CVE)

Filtered by CWE-385
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25659 2 Oracle, Python-cryptography Project 2 Communications Cloud Native Core Network Function Cloud Native Environment, Python-cryptography 2022-07-25 4.3 MEDIUM 5.9 MEDIUM
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
CVE-2020-25658 3 Fedoraproject, Python-rsa Project, Redhat 3 Fedora, Python-rsa, Openstack Platform 2022-01-01 4.3 MEDIUM 5.9 MEDIUM
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.