CVE-2020-25658

HIGH

python-rsa 2.1-4.6 - Bleichenbacher Timing Attack via RSA Decryption API

Title source: llm
STIX 2.1

Description

It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.

References (5)

Core 5
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-25658
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/sybrenstuvel/python-rsa/issues/165

Scores

CVSS v3 7.5
EPSS 0.0014
EPSS Percentile 34.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-327 CWE-385
Status published
Products (7)
fedoraproject/fedora 33
fedoraproject/fedora 34
fedoraproject/fedora 35
pypi/rsa 2.1 - 4.7PyPI
python-rsa_project/python-rsa 2.1 - 4.7
redhat/openstack_platform 13.0
redhat/openstack_platform 16.0
Published Nov 12, 2020
Tracked Since Feb 18, 2026