CVE-2025-7071
MEDIUMOberon microsystem AG's ocrypto <3.9.2 - Info Disclosure
Title source: llmDescription
Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.1.0 and prior to 3.9.2 allows an attacker to recover plaintexts via timing measurements of AES-CBC PKCS#7 decrypt operations.
Scores
CVSS v4
5.9
EPSS
0.0001
EPSS Percentile
1.0%
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-208
CWE-327
Status
published
Products (1)
Oberon microsystems AG/ocrypto
3.1.0 - 3.9.1
Published
Aug 29, 2025
Tracked Since
Feb 18, 2026