// For flags

CVE-2020-20950

 

Severity Score

5.9
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.

Un ataque de Bleichenbacher en el relleno PKCS#1 versión v1.5 para RSA en las Bibliotecas de Microchip para Aplicaciones en todas las versiones del 26-11-2018 hasta el 26-11-2018. La vulnerabilidad puede permitir a uno usar el ataque de oráculo de Bleichenbacher para descifrar un texto encriptado cifrado al hacer consultas sucesivas al servidor usando la biblioteca vulnerable, resultando en una divulgación de información remota

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-08-13 CVE Reserved
  • 2021-01-19 CVE Published
  • 2023-10-05 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microchip
Search vendor "Microchip"
Microchip Libraries For Applications
Search vendor "Microchip" for product "Microchip Libraries For Applications"
<= 2018-11-26
Search vendor "Microchip" for product "Microchip Libraries For Applications" and version " <= 2018-11-26"
-
Affected
in Apple
Search vendor "Apple"
Macos
Search vendor "Apple" for product "Macos"
--
Safe
Microchip
Search vendor "Microchip"
Microchip Libraries For Applications
Search vendor "Microchip" for product "Microchip Libraries For Applications"
<= 2018-11-26
Search vendor "Microchip" for product "Microchip Libraries For Applications" and version " <= 2018-11-26"
-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Microchip
Search vendor "Microchip"
Microchip Libraries For Applications
Search vendor "Microchip" for product "Microchip Libraries For Applications"
<= 2018-11-26
Search vendor "Microchip" for product "Microchip Libraries For Applications" and version " <= 2018-11-26"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Ietf
Search vendor "Ietf"
Public Key Cryptography Standards \#1
Search vendor "Ietf" for product "Public Key Cryptography Standards \#1"
1.5
Search vendor "Ietf" for product "Public Key Cryptography Standards \#1" and version "1.5"
-
Affected