CVE-2013-1620

Modified
Published: 08 Feb 2013, 19:00
Last modified:06 Aug 2024, 15:04

Vulnerability Summary

Overall Risk (default)
low
17/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
0.85% LOW
1% probability +0.05%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Feb 2013, 19:00
Published
Vulnerability first disclosed
06 Aug 2024, 15:04
Last Modified
Vulnerability information updated

Description

The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.85% Percentile: 75%

Techniques & Countermeasures

  • CWE-203Observable Discrepancy

    The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Affected Systems

  • canonicalubuntu_linux

    10.04 | 11.10 | 12.04 | 12.10

  • mozillanetwork_security_services

    < 3.14.3

  • oracleenterprise_manager_ops_center

    11.1 | 12.1 | 12.2

  • oracleglassfish_communications_server

    2.0

  • oracleglassfish_server

    2.1.1

  • oracleiplanet_web_proxy_server

    4.0

  • oracleiplanet_web_server

    6.1 | 7.0

  • oracleopensso

    3.0-03

  • oracletraffic_director

    11.1.1.6.0 | 11.1.1.7.0

  • oraclevm_server

    3.2

  • redhatenterprise_linux_desktop

    5.0 | 6.0

  • redhatenterprise_linux_eus

    5.9

  • redhatenterprise_linux_server

    5.0 | 6.0

  • redhatenterprise_linux_server_aus

    5.9

  • redhatenterprise_linux_workstation

    5.0 | 6.0

References (19)