Record summary

CVE-2017-1000385 has a selected CVSS score of 5.9 (medium); EIP currently links 1 catalogued exploit.

Description

The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

MetasploitScanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5Metasploit auxiliary PoCby Adam Cammack <adam_cammack[AT]rapid7.com> +4 moreNot analyzed1 file

Ruby · linked to 10 vulnerabilities

Metasploit

PoC details

References

Showing 12 of 14