PT-2025-27383 · Rlpx · Rlpx

Published

2025-06-29

·

Updated

2025-06-30

·

CVE-2015-20112

CVSS v3.1

3.4

Low

VectorAV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: RLPx version 5
Description: The issue concerns RLPx 5, which has two CTR streams based on the same key, IV, and nonce. This design flaw can facilitate decryption on a private network.
Recommendations: For RLPx version 5, consider reconfiguring the CTR streams to use distinct keys, IVs, and nonces to prevent potential decryption on private networks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2015-20112

Affected Products

Rlpx