Padding oracle attack in OSCI-Transport Library - CVE-2017-10668
Published: July 5, 2017
Vulnerability identifier: #VU7318
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-10668
CWE-ID: CWE-696
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: KoSIT
Affected software:
OSCI-Transport Library
OSCI-Transport Library
Detailed vulnerability description
The vulnerability allows a remote attacker to conduct a padding oracle attack.
The weakness exists in the encryption library due to a flaw in implementation of a number of deprecated encryption algorithms (Triple DES, AES 129, AES 192, and AES 256, all in CBC mode). A remote attacker can conduct man-in-the-middle attack to analyse the CBC mode padding and decrypt the transport encryption.
Successful exploitation of the vulnerability results in decryption of the transport encryption.
The weakness exists in the encryption library due to a flaw in implementation of a number of deprecated encryption algorithms (Triple DES, AES 129, AES 192, and AES 256, all in CBC mode). A remote attacker can conduct man-in-the-middle attack to analyse the CBC mode padding and decrypt the transport encryption.
Successful exploitation of the vulnerability results in decryption of the transport encryption.
How to mitigate CVE-2017-10668
Update to version 1.7.1.