CVE-2020-15522
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
Published:May 20, 2021
Last Modified:Jul 17, 2025
EPS:May 20, 2021
EPSS Score:0.00403
CVSS Score:5.9
Affected Products
Vendor
Product
Action
Vendor
Bouncycastle
Product
Bc-csharp
Bouncycastle
Bc-csharp
Vendor
Bouncycastle
Product
Bouncy Castle Fips .net Api
Bouncycastle
Bouncy Castle Fips .net Api
Vendor
Bouncycastle
Product
Fips Java Api
Bouncycastle
Fips Java Api
Vendor
Bouncycastle
Product
The Bouncy Castle Crypto Package For Java
Bouncycastle
The Bouncy Castle Crypto Package For Java
Vendor
Redhat
Product
Camel Quarkus
Redhat
Camel Quarkus
Vendor
Redhat
Product
Integration
Redhat
Integration
Vendor
Redhat
Product
Jboss Fuse
Redhat
Jboss Fuse
Vendor
Redhat
Product
Jbosseapxp
Redhat
Jbosseapxp
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
