Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fw6m-5fq2-8fqr

Опубликовано: 29 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.9

Описание

Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.1.0 and prior to 3.9.2 allows an attacker to recover plaintexts via timing measurements of AES-CBC PKCS#7 decrypt operations.

Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.1.0 and prior to 3.9.2 allows an attacker to recover plaintexts via timing measurements of AES-CBC PKCS#7 decrypt operations.

EPSS

Процентиль: 1%
0.00009
Низкий

5.9 Medium

CVSS4

Дефекты

CWE-208

Связанные уязвимости

nvd
5 месяцев назад

Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.1.0 and prior to 3.9.2 allows an attacker to recover plaintexts via timing measurements of AES-CBC PKCS#7 decrypt operations.

EPSS

Процентиль: 1%
0.00009
Низкий

5.9 Medium

CVSS4

Дефекты

CWE-208