Impact
Eclipse Milo versions 0.6.0 through 1.1.4 process username tokens by returning distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures. An on-path attacker who captures a victim's Basic128Rsa15 encrypted username token can send repeated unauthenticated ActivateSession requests, relying on the differing error responses to perform a padding oracle attack. This allows the attacker to recover the victim's password and authenticate using the recovered credentials. The flaw is a classic padding oracle weakness (CWE-204) with full confidentiality and authentication compromise.
Affected Systems
The vulnerable product is Eclipse Milo under the Eclipse Foundation. The affected range is versions 0.6.0 through 1.1.4 inclusive. No explicit sub-product variants are listed in the data.
Risk and Exploitability
The CVSS base score is 9.1, indicating high severity. EPSS data is not available and the vulnerability is not listed in CISA KEV. The attack requires an on-path position to intercept a Basic128Rsa15 token and the ability to send many ActivateSession requests; it does not require privileged user interaction, making exploitation feasible for network attackers against exposed Milo services.
OpenCVE Enrichment