CVE-2020-20949

MEDIUMCVSS 5.9/10EPSS 0.92%

Last modified

CVE-2020-20949 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.. EPSS estimates a 0.92% chance of exploitation in the next 30 days.

Description

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.

Metrics

CVSS 3.1
5.9/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.92%

55.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
StStm32cubef0All versions
StStm32cubef1All versions
StStm32cubef2All versions
StStm32cubef3All versions
StStm32cubef4All versions
StStm32cubef7All versions
StStm32cubeg0All versions
StStm32cubeg4All versions
StStm32cubeh7All versions
StStm32cubeideAll versions
StStm32cubel0All versions
StStm32cubel1All versions
StStm32cubel4All versions
StStm32cubel4\+All versions
StStm32cubel5All versions
StStm32cubemonitorAll versions
StStm32cubemp1All versions
StStm32cubemxAll versions
StStm32cubeprogrammerAll versions
StStm32cubewbAll versions
StStm32cubewlAll versions
IetfPublic Key Cryptography Standards \#11.5

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-20949?
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.
How severe is CVE-2020-20949?
CVE-2020-20949 has a CVSS score of 5.9/10 (MEDIUM severity). The EPSS model estimates a 0.92% probability of exploitation in the next 30 days.
How do I fix CVE-2020-20949?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-20949?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST