cbcvebase.
CVE-2020-25658
published 2020-11-12

CVE-2020-25658: It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the…

PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.63%
73.6th percentile
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianpython-rsa
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
paloaltopan-os
python-rsa_projectpython-rsa>= 2.1 < 4.74.7
redhatopenstack_platform
redhatopenstack_platform
rustcryptorsa>= 2.1 < 4.74.7
sybren_a_st_velpython-rsa

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.