PT-2023-24616 · Briar · Briar

Kenny Paterson

+1

·

Published

2023-05-24

·

Updated

2025-01-16

·

CVE-2023-33982

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Briar versions prior to 1.5.3
Description The issue affects the Bramble Handshake Protocol (BHP) in Briar, allowing eavesdroppers to decrypt network traffic between two accounts if they later compromise both accounts. However, the eavesdropping is typically impractical because BHP runs over an encrypted session that uses the Tor hidden service protocol.
Recommendations For versions prior to 1.5.3, update to version 1.5.3 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information until the update is applied.

Exploit

Fix

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2023-33982

Affected Products

Briar