PT-2005-2764 · Nist+1 · Advanced Encryption Standard+1

Published

2005-05-26

·

Updated

2008-09-05

·

CVE-2005-1797

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Advanced Encryption Standard (AES) (affected versions not specified)
Description The design of Advanced Encryption Standard (AES) allows remote attackers to recover AES keys via timing attacks on S-box lookups. These lookups are difficult to perform in constant time in AES implementations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1797

Affected Products

Advanced Encryption Standard
Openssl