CVE Feed

    Dashboard / CVE / CVE-2020-15522

    CVE-2020-15522

    Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.

    Published:May 20, 2021
    Last Modified:Jul 17, 2025
    EPS:May 20, 2021
    EPSS Score:0.00403
    CVSS Score:5.9

    Affected Products

    Vendor
    Bouncycastle
    Product
    Bc-csharp
    Vendor
    Bouncycastle
    Product
    Bouncy Castle Fips .net Api
    Vendor
    Bouncycastle
    Product
    Fips Java Api
    Vendor
    Bouncycastle
    Product
    The Bouncy Castle Crypto Package For Java
    Vendor
    Redhat
    Product
    Camel Quarkus
    Vendor
    Redhat
    Product
    Integration
    Vendor
    Redhat
    Product
    Jboss Fuse
    Vendor
    Redhat
    Product
    Jbosseapxp

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High