Vulnerability identifier: #VU82583
Vulnerability risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-203
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
GSKit-Crypto
Other software /
Other software solutions
Vendor: IBM Corporation
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to timing-based side channel in the RSA Decryption implementation. A remote attacker can send an overly large number of trial messages for decryption and gain unauthorized access to sensitive information on the system.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
GSKit-Crypto: All versions
External links
http://www.ibm.com/support/pages/node/7022413
http://www.ibm.com/support/pages/node/7022414
http://www.ibm.com/support/pages/node/7010369
http://exchange.xforce.ibmcloud.com/vulnerabilities/257132
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.