Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.

Project Subscriptions

Vendors Products
Public Key Cryptography Standards \#1 Subscribe
Stm32cubef0 Subscribe
Stm32cubef1 Subscribe
Stm32cubef2 Subscribe
Stm32cubef3 Subscribe
Stm32cubef4 Subscribe
Stm32cubef7 Subscribe
Stm32cubeg0 Subscribe
Stm32cubeg4 Subscribe
Stm32cubeh7 Subscribe
Stm32cubeide Subscribe
Stm32cubel0 Subscribe
Stm32cubel1 Subscribe
Stm32cubel4 Subscribe
Stm32cubel4\+ Subscribe
Stm32cubel5 Subscribe
Stm32cubemonitor Subscribe
Stm32cubemp1 Subscribe
Stm32cubemx Subscribe
Stm32cubeprogrammer Subscribe
Stm32cubewb Subscribe
Stm32cubewl Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-13728 Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T14:22:25.552Z

Reserved: 2020-08-13T00:00:00

Link: CVE-2020-20949

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-01-20T16:15:14.007

Modified: 2024-11-21T05:12:19.903

Link: CVE-2020-20949

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses