Description
Under certain conditions, RSA operations performed by IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 may exhibit non-constant-time behavior. This could allow a remote attacker to obtain sensitive information using a timing-based attack. IBM X-Force ID: 257676.
Published: 2024-03-26
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-38005 Under certain conditions, RSA operations performed by IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 may exhibit non-constant-time behavior. This could allow a remote attacker to obtain sensitive information using a timing-based attack. IBM X-Force ID: 257676.
History

Fri, 25 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm aix
Ibm i
Linux
Linux linux Kernel
CPEs cpe:2.3:a:ibm:common_cryptographic_architecture:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Vendors & Products Ibm aix
Ibm i
Linux
Linux linux Kernel

Subscriptions

Ibm Aix Common Cryptographic Architecture I
Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2024-08-05T16:12:49.907Z

Reserved: 2023-05-23T00:32:05.085Z

Link: CVE-2023-33855

cve-icon Vulnrichment

Updated: 2024-08-02T15:54:12.608Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-26T14:15:07.903

Modified: 2025-07-25T21:09:49.733

Link: CVE-2023-33855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-13T11:32:17Z

Weaknesses