Vulnerability identifier: #VU7318
Vulnerability risk: Low
Exploitation vector: Network
Exploit availability: No
The vulnerability allows a remote attacker to conduct a padding oracle attack.
The weakness exists in the encryption library due to a flaw in implementation of a number of deprecated encryption algorithms (Triple DES, AES 129, AES 192, and AES 256, all in CBC mode). A remote attacker can conduct man-in-the-middle attack to analyse the CBC mode padding and decrypt the transport encryption.
Successful exploitation of the vulnerability results in decryption of the transport encryption.
Update to version 1.7.1.
Vulnerable software versions
OSCI-Transport Library: 1.6.1
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?