SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-6298

The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain cleartext data via a Million Message Attack (MMA).

MEDIUM 5.3EPSS 2.25%

Does this matter?

Lower severity and a low EPSS score (2.25%). Track it; it rarely justifies an emergency change on its own.

Description

The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain cleartext data via a Million Message Attack (MMA).

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
2.25% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
latchset/jwcrypto
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.