Exploit for #VU49086 Comparison using wrong factors in The Bouncy Castle Crypto Package For Java


Published: 2020-12-23 | Updated: 2021-01-06

Vulnerability identifier: #VU49086

Vulnerability risk: High

CVSSv3.1: 7.3 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C]

CVE-ID: CVE-2020-28052

CWE-ID: CWE-1025

Exploitation vector: Network

Exploits in database: 2

Impact: Code execution

Vulnerable software:
The Bouncy Castle Crypto Package For Java
Universal components / Libraries / Libraries used by multiple products

Vendor: Legion of the Bouncy Castle Inc.