CVE-2020-20949

MEDIUM

STM32Cube Cryptographic Library - Remote Information Disclosure via Bleichenbacher's PKCS #1 v1.5 Oracle Attack

Title source: llm
STIX 2.1

Description

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.

References (5)

Core 5

Scores

CVSS v3 5.9
EPSS 0.0092
EPSS Percentile 56.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-327
Status published
Products (22)
ietf/public_key_cryptography_standards_\#1 1.5
st/stm32cubef0
st/stm32cubef1
st/stm32cubef2
st/stm32cubef3
st/stm32cubef4
st/stm32cubef7
st/stm32cubeg0
st/stm32cubeg4
st/stm32cubeh7
... and 12 more
Published Jan 20, 2021
Tracked Since Feb 18, 2026