CVE-2018-11057

Severity
5.9MEDIUM
EPSS
0.6%
top 29.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 31
Latest updateMay 13

Description

RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) contains a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be able to recover a RSA key.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages13 packages

CVEListV5rsa/bsafe_micro_edition_suiteunspecified4.0.11+1
NVDdell/bsafe4.0.04.0.11+1
NVDoracle/core_rdbms5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fg5g-qjmw-2fv3: RSA BSAFE Micro Edition Suite, versions prior to 42022-05-13
CVEList
CVE-2018-11057: RSA BSAFE Micro Edition Suite, versions prior to 42018-08-31