CVE-2017-13098
BouncyCastle JCE TLS Bleichenbacher/ROBOT
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable application. This vulnerability is referred to as "ROBOT."
BouncyCastle TLS, en versiones anteriores a la 1.0.3 cuando está configurado para utilizar la JCE (Java Cryptography Extension) para funciones criptográficas, proporciona un oráculo de Bleichenbacher débil cuando se negocia una suite de cifrado TLS que utiliza un intercambio de claves RSA. Un atacante puede recuperar la clave privada desde una aplicación vulnerable. Esta vulnerabilidad es conocida como "ROBOT".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-08-22 CVE Reserved
- 2017-12-13 CVE Published
- 2023-06-14 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-203: Observable Discrepancy
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.kb.cert.org/vuls/id/144389 | Issue Tracking | |
http://www.securityfocus.com/bid/102195 | Third Party Advisory | |
https://robotattack.org | Issue Tracking | |
https://security.netapp.com/advisory/ntap-20171222-0001 | Issue Tracking | |
https://www.oracle.com/security-alerts/cpuoct2020.html | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/bcgit/bc-java/commit/a00b684465b38d722ca9a3543b8af8568e6bad5c | 2020-10-20 |
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00011.html | 2020-10-20 | |
https://www.debian.org/security/2017/dsa-4072 | 2020-10-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bouncycastle Search vendor "Bouncycastle" | Legion-of-the-bouncy-castle-java-crytography-api Search vendor "Bouncycastle" for product "Legion-of-the-bouncy-castle-java-crytography-api" | < 1.59 Search vendor "Bouncycastle" for product "Legion-of-the-bouncy-castle-java-crytography-api" and version " < 1.59" | - |
Affected
|