CVE-2020-15522
Last modified
CVE-2020-15522 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.. EPSS estimates a 1.52% chance of exploitation in the next 30 days.
Description
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bouncycastle | Bc-Csharp | < 1.8.7 |
| Bouncycastle | Bouncy Castle Fips .Net Api | < 1.0.1.1 |
| Bouncycastle | Fips Java Api | < 1.0.1.2 |
| Bouncycastle | Fips Java Api | >= 1.0.2, < 1.0.2.1 |
| Bouncycastle | The Bouncy Castle Crypto Package For Java | < 1.66 |
References
- https://github.com/bcgit/bc-csharp/wiki/CVE-2020-15522Third Party Advisory
- https://github.com/bcgit/bc-java/wiki/CVE-2020-15522Third Party Advisory
- https://www.bouncycastle.org/releasenotes.htmlRelease Notes, Vendor Advisory
- https://github.com/bcgit/bc-csharp/wiki/CVE-2020-15522Third Party Advisory
- https://github.com/bcgit/bc-java/wiki/CVE-2020-15522Third Party Advisory
- https://www.bouncycastle.org/releasenotes.htmlRelease Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-15522?
How severe is CVE-2020-15522?
How do I fix CVE-2020-15522?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-15515The turn extension through 0.3.2 for TYPO3 allows Remote Cod…8.8
- CVE-2020-15516The mm_forum extension through 1.9.5 for TYPO3 allows XSS th…5.4
- CVE-2020-15517The ke_search (aka Faceted Search) extension through 2.8.2, …5.4
- CVE-2020-15518VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam…8.8
- CVE-2020-1552An elevation of privilege vulnerability exists when the Wind…8
- CVE-2020-15521Zoho ManageEngine Applications Manager before 14 build 14730…6.1
- CVE-2020-15523In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through…7.8
- CVE-2020-15525GitLab EE 11.3 through 13.1.2 has Incorrect Access Control b…5.3
- CVE-2020-15526In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the…5.9
- CVE-2020-15528An issue was discovered in GOG Galaxy Client 2.0.17. Local e…7.8
- CVE-2020-15529An issue was discovered in GOG Galaxy Client 2.0.17. Local e…7.8
- CVE-2020-1553An elevation of privilege vulnerability exists when the Wind…7.8
Are you affected by CVE-2020-15522?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
