5.9
CVSSv3

CVE-2020-25658

Published: 12/11/2020 Updated: 12/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

python-rsa project python-rsa

redhat openstack platform 16.0

redhat openstack platform 13.0

fedoraproject fedora 33

fedoraproject fedora 34

fedoraproject fedora 35

Vendor Advisories

Synopsis Moderate: Red Hat Ceph Storage 43 Security and Bug Fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New packages for Red Hat Ceph Storage 43 are now available on Red Hat Enterprise Linux 85Red Hat Pr ...
Debian Bug report logs - #974685 python-rsa: CVE-2020-25658 Package: src:python-rsa; Maintainer for src:python-rsa is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 13 Nov 2020 18:48:02 UTC Severity: important Tags: security, ...
A flaw was found in python-rsa, where it is vulnerable to Bleichenbacher timing attacks This flaw allows an attacker, via the RSA decryption API, to decrypt parts of the ciphertext encrypted with RSA The highest threat from this vulnerability is to confidentiality (CVE-2020-25658) ...
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS ...

Github Repositories

python-tda-bug-hunt-0 DEPENDENCY #oauth2client==13 VULNERABLE DEPENDENCY IN THE PACKAGE TREE #rsa==314 VULNERABILITIES WS-2013-0018 WS-2012-0012 CVE-2020-25658 CVE-2020-13757 CVE-2016-1494