Lucene search

K
githubGitHub Advisory DatabaseGHSA-J225-CVW7-QRX7
HistoryJan 05, 2024 - 6:30 a.m.

PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption

2024-01-0506:30:19
CWE-203
GitHub Advisory Database
github.com
28
pycryptodome
pycryptodomex
side-channel leakage
oaep decryption
manger attack
software

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

37.2%

PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.

Affected configurations

Vulners
Node
pycryptodomepycryptodomeRange<3.19.1
OR
pycryptodomexRange<3.19.1
VendorProductVersionCPE
pycryptodomepycryptodome*cpe:2.3:a:pycryptodome:pycryptodome:*:*:*:*:*:*:*:*
*pycryptodomex*cpe:2.3:a:*:pycryptodomex:*:*:*:*:*:*:*:*

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

37.2%