CVE-2020-15522
published 2021-05-20CVE-2020-15522: Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math…
PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.52%
72.0th percentile
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-csharp | < 1.8.7 | 1.8.7 |
| bouncycastle | bouncy_castle_fips_net_api | < 1.0.1.1 | 1.0.1.1 |
| bouncycastle | fips_java_api | < 1.0.1.2 | 1.0.1.2 |
| bouncycastle | fips_java_api | >= 1.0.2 < 1.0.2.1 | 1.0.2.1 |
| bouncycastle | the_bouncy_castle_crypto_package_for_java | < 1.66 | 1.66 |
| debian | bouncycastle | < bouncycastle 1.68-1 (bookworm) | bouncycastle 1.68-1 (bookworm) |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bouncycastle: Timing issue within the EC math library
vendor_redhat·2021-05-20·CVSS 5.9
CVE-2020-15522 [MEDIUM] CWE-367 bouncycastle: Timing issue within the EC math library
bouncycastle: Timing issue within the EC math library
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
A flaw was found in bouncycastle. A timing issue within the EC math library can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
Package: bouncycastle (Red Hat build of Quarkus) - Not affected
Package: bouncycastle (Red Hat Decision Manager 7) - Not affected
Package: bouncycastle (Red Hat Enterpri
Debian
CVE-2020-15522: bouncycastle - Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1....
vendor_debian·2020·CVSS 5.9
CVE-2020-15522 [MEDIUM] CVE-2020-15522: bouncycastle - Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1....
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
Scope: local
bookworm: resolved (fixed in 1.68-1)
bullseye: resolved (fixed in 1.68-1)
forky: resolved (fixed in 1.68-1)
sid: resolved (fixed in 1.68-1)
trixie: resolved (fixed in 1.68-1)
OSV
Timing based private key exposure in Bouncy Castle
osv·2021-08-13
CVE-2020-15522 [MEDIUM] Timing based private key exposure in Bouncy Castle
Timing based private key exposure in Bouncy Castle
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.2.1, BC before 1.66, BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
GHSA
Timing based private key exposure in Bouncy Castle
ghsa·2021-08-13
CVE-2020-15522 [MEDIUM] CWE-203 Timing based private key exposure in Bouncy Castle
Timing based private key exposure in Bouncy Castle
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.2.1, BC before 1.66, BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
OSV
CVE-2020-15522: Bouncy Castle BC Java before 1
osv·2021-05-20·CVSS 5.9
CVE-2020-15522 [MEDIUM] CVE-2020-15522: Bouncy Castle BC Java before 1
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/bcgit/bc-csharp/wiki/CVE-2020-15522https://github.com/bcgit/bc-java/wiki/CVE-2020-15522https://security.netapp.com/advisory/ntap-20210622-0007/https://www.bouncycastle.org/releasenotes.htmlhttps://github.com/bcgit/bc-csharp/wiki/CVE-2020-15522https://github.com/bcgit/bc-java/wiki/CVE-2020-15522https://security.netapp.com/advisory/ntap-20210622-0007/https://www.bouncycastle.org/releasenotes.html
2021-05-20
Published