cbcvebase.
CVE-2020-15522
published 2021-05-20

CVE-2020-15522: Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math…

PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.52%
72.0th percentile
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.

Affected

6 ranges
VendorProductVersion rangeFixed in
bouncycastlebc-csharp< 1.8.71.8.7
bouncycastlebouncy_castle_fips_net_api< 1.0.1.11.0.1.1
bouncycastlefips_java_api< 1.0.1.21.0.1.2
bouncycastlefips_java_api>= 1.0.2 < 1.0.2.11.0.2.1
bouncycastlethe_bouncy_castle_crypto_package_for_java< 1.661.66
debianbouncycastle< bouncycastle 1.68-1 (bookworm)bouncycastle 1.68-1 (bookworm)

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.