#VU82583 Observable discrepancy in GSKit-Crypto


Published: 2023-10-31

Vulnerability identifier: #VU82583

Vulnerability risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-33850

CWE-ID: CWE-203

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
GSKit-Crypto
Other software / Other software solutions

Vendor: IBM Corporation

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to timing-based side channel in the RSA Decryption implementation. A remote attacker can send an overly large number of trial messages for decryption and gain unauthorized access to sensitive information on the system.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

GSKit-Crypto: All versions


External links
http://www.ibm.com/support/pages/node/7022413
http://www.ibm.com/support/pages/node/7022414
http://www.ibm.com/support/pages/node/7010369
http://exchange.xforce.ibmcloud.com/vulnerabilities/257132


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability