PT-2024-15383 · Cryptolib · Cryptolib

Hubert Kario

+1

·

Published

2024-02-05

·

Updated

2026-03-16

·

CVE-2024-0202

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions cryptlib (affected versions not specified)
Description A security issue has been identified in the cryptlib cryptographic library when it is compiled with support for RSA key exchange ciphersuites in TLS. This makes it vulnerable to the timing variant of the Bleichenbacher attack. An attacker who can establish a large number of connections to the server can decrypt RSA ciphertexts or forge signatures using the server's certificate.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2024-0202

Affected Products

Cryptolib