CVE-2024-30171
published 2024-05-14CVE-2024-30171: An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of…
PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.90%
55.7th percentile
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bouncycastle | < bouncycastle 1.80-1 (forky) | bouncycastle 1.80-1 (forky) |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bouncy Castle vulnerabilities
vendor_ubuntu·2026-03-18·CVSS 5.3
CVE-2025-8916 [MEDIUM] Bouncy Castle vulnerabilities
Title: Bouncy Castle vulnerabilities
Summary: Several security issues were fixed in Bouncy Castle.
It was discovered that Bouncy Castle did not sanitize user input when
inserting it into an LDAP search filter. An attacker could possibly use
this issue to perform an LDAP injection attack. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2023-33201)
It was discovered that Bouncy Castle incorrectly handled specially crafted
F2m parameters in the ECCurve algorithm. An attacker could possibly use
this issue to cause Bouncy Castle to use excessive resources, leading to a
denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-29857)
It was discovered that Bouncy
CISA ICS
Siemens SIDIS Prime
cisa_ics·2026-03-12·CVSS 7.5
[HIGH] Siemens SIDIS Prime
ICS Advisory
##
Siemens SIDIS Prime
Release DateMarch 12, 2026
Alert CodeICSA-26-071-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
SIDIS Prime before V4.0.800 is affected by multiple vulnerabilities in the components OpenSSL, SQLite, and several Node.js packages as described below. Siemens has released a new version of SIDIS Prime and recommends to update to the latest version.
The following versions of Siemens SIDIS Prime are affected:
- SIDIS Prime vers:intdot/<4.0.800 (CVE-2024-29857, CVE-2024-30171, CVE-2024-30172, CVE-2024-41996, CVE-2025-6965, CVE-2025-7783, CVE-2025-9230, CVE-2025-9232, CVE-2025-9670, CVE-2025-12816, CVE-2025-15284, CVE-2025-58751, CVE-2025-58752, CVE-2025-58754, CVE-202
Red Hat
bc-java: BouncyCastle vulnerable to a timing variant of Bleichenbacher (Marvin Attack)
vendor_redhat·2024-04-18·CVSS 5.9
CVE-2024-30171 [MEDIUM] CWE-208 bc-java: BouncyCastle vulnerable to a timing variant of Bleichenbacher (Marvin Attack)
bc-java: BouncyCastle vulnerable to a timing variant of Bleichenbacher (Marvin Attack)
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.
A flaw was found in the Bouncy Castle Java cryptography APIs. Affected versions of the org.bouncycastle:bcprov-jdk18on package are vulnerable to Observable Timing Discrepancy via the PKCS#1 1.5 and OAEP decryption process (a.k.a. Marvin Attack). An attacker can recover cipher-texts via a side-channel attack by exploiting the Marvin security flaw. The PKCS#1 1.5 attack vector leaks data via javax.crypto.Cipher exceptions and the OAEP interface vector leaks via the bit size of the decrypted data.
Mitigation: Mitigation for this issue
Debian
CVE-2024-30171: bouncycastle - An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1...
vendor_debian·2024·CVSS 5.9
CVE-2024-30171 [MEDIUM] CVE-2024-30171: bouncycastle - An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1...
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.80-1)
sid: resolved (fixed in 1.80-1)
trixie: resolved (fixed in 1.80-1)
OSV
bouncycastle vulnerabilities
osv·2026-03-18·CVSS 5.3
CVE-2023-33201 [MEDIUM] bouncycastle vulnerabilities
bouncycastle vulnerabilities
It was discovered that Bouncy Castle did not sanitize user input when
inserting it into an LDAP search filter. An attacker could possibly use
this issue to perform an LDAP injection attack. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2023-33201)
It was discovered that Bouncy Castle incorrectly handled specially crafted
F2m parameters in the ECCurve algorithm. An attacker could possibly use
this issue to cause Bouncy Castle to use excessive resources, leading to a
denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-29857)
It was discovered that Bouncy Castle leaked timing information when
handling exceptions during an RSA
OSV
CVE-2024-30171: An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1
osv·2024-05-14·CVSS 5.9
CVE-2024-30171 [MEDIUM] CVE-2024-30171: An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.
OSV
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
osv·2024-05-14
CVE-2024-30171 [MEDIUM] Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.
GHSA
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
ghsa·2024-05-14
CVE-2024-30171 [MEDIUM] CWE-203 Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.
No detection rules found.
No public exploits indexed.
https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9030171https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9030171https://security.netapp.com/advisory/ntap-20240614-0008/https://www.bouncycastle.org/latest_releases.htmlhttps://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9030171https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9030171https://security.netapp.com/advisory/ntap-20240614-0008/https://www.bouncycastle.org/latest_releases.html
2024-05-14
Published