PT-2025-27383 · Rlpx · Rlpx
Published
2025-06-29
·
Updated
2025-06-30
·
CVE-2015-20112
CVSS v3.1
3.4
Low
| Vector | AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
RLPx version 5
Description:
The issue concerns RLPx 5, which has two CTR streams based on the same key, IV, and nonce. This design flaw can facilitate decryption on a private network.
Recommendations:
For RLPx version 5, consider reconfiguring the CTR streams to use distinct keys, IVs, and nonces to prevent potential decryption on private networks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rlpx