CVE-2025-7071

Oberon microsystem AG's ocrypto <3.9.2 - Info Disclosure

Title source: llm

Description

Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.1.0 and prior to 3.9.2 allows an attacker to recover plaintexts via timing measurements of AES-CBC PKCS#7 decrypt operations.

Scores

EPSS 0.0001
EPSS Percentile 0.8%

Classification

CWE
CWE-327 CWE-208
Status draft

Timeline

Published Aug 29, 2025
Tracked Since Feb 18, 2026