CVE Feed

    Dashboard / CVE / CVE-2020-20949

    CVE-2020-20949

    Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.

    Published:Jan 20, 2021
    Last Modified:Nov 21, 2024
    EPS:Jan 20, 2021
    EPSS Score:0.0028
    CVSS Score:5.9

    Affected Products

    Vendor
    Ietf
    Product
    Public Key Cryptography Standards \#1
    Vendor
    St
    Product
    Stm32cubef0
    Vendor
    St
    Product
    Stm32cubef1
    Vendor
    St
    Product
    Stm32cubef2
    Vendor
    St
    Product
    Stm32cubef3
    Vendor
    St
    Product
    Stm32cubef4
    Vendor
    St
    Product
    Stm32cubef7
    Vendor
    St
    Product
    Stm32cubeg0
    Vendor
    St
    Product
    Stm32cubeg4
    Vendor
    St
    Product
    Stm32cubeh7
    Vendor
    St
    Product
    Stm32cubeide
    Vendor
    St
    Product
    Stm32cubel0
    Vendor
    St
    Product
    Stm32cubel1
    Vendor
    St
    Product
    Stm32cubel4
    Vendor
    St
    Product
    Stm32cubel4\+
    Vendor
    St
    Product
    Stm32cubel5
    Vendor
    St
    Product
    Stm32cubemonitor
    Vendor
    St
    Product
    Stm32cubemp1
    Vendor
    St
    Product
    Stm32cubemx
    Vendor
    St
    Product
    Stm32cubeprogrammer
    Vendor
    St
    Product
    Stm32cubewb
    Vendor
    St
    Product
    Stm32cubewl

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High