SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-0169

The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding,…

LOW 2.6EPSS 35.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 35.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.

CVSS 2.0
2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
EPSS
35.58% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
openssl/openssl · oracle/openjdk · polarssl/polarssl
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.