CVE-2018-16868
CVE-2018-16868
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.7EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
03 dic 2018Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.
CVSS:3.0/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Productos afectados
[UNKNOWN] · gnutls¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →