3.3
CVSSv2

CVE-2018-16869

Published: 03/12/2018 Updated: 03/02/2023
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 5.7 | Impact Score: 4.7 | Exploitability Score: 0.5
VMScore: 295
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nettle project nettle

Vendor Advisories

A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v15 data An attacker who is able to run a process on the same physical core as the victim process could use this flaw extract plain text or, in some cases, downgrade any TLS connections to a vulnerable serve ...