CVE-2025-7071

MEDIUM

Oberon microsystem AG's ocrypto <3.9.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.1.0 and prior to 3.9.2 allows an attacker to recover plaintexts via timing measurements of AES-CBC PKCS#7 decrypt operations.

Scores

CVSS v4 5.9
EPSS 0.0001
EPSS Percentile 1.0%
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-208 CWE-327
Status published
Products (1)
Oberon microsystems AG/ocrypto 3.1.0 - 3.9.1
Published Aug 29, 2025
Tracked Since Feb 18, 2026