CVE-2019-1563

Advisory lineage Upstream: 0 Downstream: 30
Modified
Published: 10 Sept 2019, 16:58
Last modified:17 Sept 2024, 01:11

Vulnerability Summary

Overall Risk (default)
low
17/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
1.12% LOW
1% probability -0.51%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

10 Sept 2019, 16:58
Published
Vulnerability first disclosed
17 Sept 2024, 01:11
Last Modified
Vulnerability information updated

Description

In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not affected if they use a certificate together with the private RSA key to the CMS_decrypt or PKCS7_decrypt functions to select the correct recipient info to decrypt. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).

CVSS Metrics

  • v3.1LOWScore: 3.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 1.12% Percentile: 79%

Techniques & Countermeasures

  • CWE-203Observable Discrepancy

    The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

  • CWE-327Use of a Broken or Risky Cryptographic Algorithm

    The product uses a broken or risky cryptographic algorithm or protocol.

Affected Systems

  • UnknownOpenSSL

    ≥ 1.0.2, ≤ 1.0.2s | ≥ 1.1.0, ≤ 1.1.0k | ≥ 1.1.1, ≤ 1.1.1c | Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c) | Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k) | Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s)

References (30)