// For flags

CVE-2020-20949

 

Severity Score

5.9
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.

El ataque de Bleichenbacher en el relleno PKCS #1 v1.5 para RSA en la expansión del software de la biblioteca de firmware criptográfico STM32 para STM32Cube (UM1924). La vulnerabilidad puede permitir que uno use un ataque de oráculo de Bleichenbacher para descifrar un texto cifrado encriptado al hacer consultas sucesivas al servidor usando la biblioteca vulnerable, resultando en la divulgación de información remota

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-08-13 CVE Reserved
  • 2021-01-20 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-11-09 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
St
Search vendor "St"
Stm32cubef0
Search vendor "St" for product "Stm32cubef0"
--
Affected
St
Search vendor "St"
Stm32cubef1
Search vendor "St" for product "Stm32cubef1"
--
Affected
St
Search vendor "St"
Stm32cubef2
Search vendor "St" for product "Stm32cubef2"
--
Affected
St
Search vendor "St"
Stm32cubef3
Search vendor "St" for product "Stm32cubef3"
--
Affected
St
Search vendor "St"
Stm32cubef4
Search vendor "St" for product "Stm32cubef4"
--
Affected
St
Search vendor "St"
Stm32cubef7
Search vendor "St" for product "Stm32cubef7"
--
Affected
St
Search vendor "St"
Stm32cubeg0
Search vendor "St" for product "Stm32cubeg0"
--
Affected
St
Search vendor "St"
Stm32cubeg4
Search vendor "St" for product "Stm32cubeg4"
--
Affected
St
Search vendor "St"
Stm32cubeh7
Search vendor "St" for product "Stm32cubeh7"
--
Affected
St
Search vendor "St"
Stm32cubeide
Search vendor "St" for product "Stm32cubeide"
--
Affected
St
Search vendor "St"
Stm32cubel0
Search vendor "St" for product "Stm32cubel0"
--
Affected
St
Search vendor "St"
Stm32cubel1
Search vendor "St" for product "Stm32cubel1"
--
Affected
St
Search vendor "St"
Stm32cubel4
Search vendor "St" for product "Stm32cubel4"
--
Affected
St
Search vendor "St"
Stm32cubel4\+
Search vendor "St" for product "Stm32cubel4\+"
--
Affected
St
Search vendor "St"
Stm32cubel5
Search vendor "St" for product "Stm32cubel5"
--
Affected
St
Search vendor "St"
Stm32cubemonitor
Search vendor "St" for product "Stm32cubemonitor"
--
Affected
St
Search vendor "St"
Stm32cubemp1
Search vendor "St" for product "Stm32cubemp1"
--
Affected
St
Search vendor "St"
Stm32cubemx
Search vendor "St" for product "Stm32cubemx"
--
Affected
St
Search vendor "St"
Stm32cubeprogrammer
Search vendor "St" for product "Stm32cubeprogrammer"
--
Affected
St
Search vendor "St"
Stm32cubewb
Search vendor "St" for product "Stm32cubewb"
--
Affected
St
Search vendor "St"
Stm32cubewl
Search vendor "St" for product "Stm32cubewl"
--
Affected
Ietf
Search vendor "Ietf"
Public Key Cryptography Standards \#1
Search vendor "Ietf" for product "Public Key Cryptography Standards \#1"
1.5
Search vendor "Ietf" for product "Public Key Cryptography Standards \#1" and version "1.5"
-
Affected