CVE-2017-10668

MEDIUM

OSCI Transport Library 1.6.1 (Java) and 1.6 (.NET) - Padding Oracle via CBC Mode

Title source: llm
STIX 2.1

Description

A Padding Oracle exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). Under an MITM condition within the OSCI infrastructure, an attacker needs to send crafted protocol messages to analyse the CBC mode padding in order to decrypt the transport encryption.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/fulldisclosure/2017/Jun/44

Scores

CVSS v3 5.9
EPSS 0.0033
EPSS Percentile 24.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-327
Status published
Products (2)
xoev/osci_transport_library 1.6
xoev/osci_transport_library 1.6.1
Published Jun 30, 2017
Tracked Since Feb 18, 2026