← back
CVE-2017-13098highCWE-203

BouncyCastle JCE TLS Bleichenbacher/ROBOT

41Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 7.5epss 24%
from disclosure to weapon0 days
Published on NVDDec 13
metasploitJun 17
exploitation probability
24%top 2% of all CVEs
observed exploitation
nono source reports it
In short

BouncyCastle TLS versions before 1.0.3 have a flaw in how they handle RSA encryption during TLS connections, allowing attackers to potentially recover the private encryption key through repeated connection attempts. This is a serious vulnerability that affects the security of encrypted communications.

Technical detail

BouncyCastle JCE TLS prior to 1.0.3 contains a Bleichenbacher oracle vulnerability (ROBOT attack) when RSA key exchange cipher suites are negotiated. The vulnerability stems from timing or error message differences in RSA decryption handling, enabling an attacker to distinguish valid from invalid ciphertexts and gradually recover the server's private key without authentication.

Summary generated and translated by AI from the official description.
BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable application. This vulnerability is referred to as "ROBOT."
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N