← voltar
CVE-2025-7071

Timing side-channel vulnerability in AES-CBC decryption with PKCS#7 padding in ocrypto library

CVSS 5.9 MEDIUMEPSS 0.1%CWE-208CWE-327
Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.1.0 and prior to 3.9.2 allows an attacker to recover plaintexts via timing measurements of AES-CBC PKCS#7 decrypt operations.
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →