CVE-2020-25658

Severity
5.9MEDIUM
EPSS
0.3%
top 51.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12
Latest updateApr 30

Description

It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

CVEListV5sybren_a._stüvel/python-rsaafter 3.0 (inclusive)
PyPIrsa2.14.7
NVDredhat/openstack_platform13.0, 16.0+1

Also affects: Fedora 33, 34, 35

🔴Vulnerability Details

4
GHSA
Timing attacks in python-rsa2021-04-30
OSV
Timing attacks in python-rsa2021-04-30
CVEList
CVE-2020-25658: It was found that python-rsa is vulnerable to Bleichenbacher timing attacks2020-11-12
OSV
CVE-2020-25658: It was found that python-rsa is vulnerable to Bleichenbacher timing attacks2020-11-12

📋Vendor Advisories

2
Red Hat
python-rsa: bleichenbacher timing oracle attack against RSA decryption2020-11-09
Debian
CVE-2020-25658: python-rsa - It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An ...2020

💬Community

1
Bugzilla
CVE-2020-25658 python-rsa: bleichenbacher timing oracle attack against RSA decryption2020-10-21
CVE-2020-25658 (MEDIUM CVSS 5.9) | It was found that python-rsa is vul | cvebase.io