CVE-2017-13098
BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 24.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable application. This vulnerability is referred to as "ROBOT."
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 24.28% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- bouncycastle/bc-java
- Source
- cret@cert.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00011.html
- http://www.kb.cert.org/vuls/id/144389Issue Tracking, Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/102195Third Party Advisory, VDB Entry
- https://github.com/bcgit/bc-java/commit/a00b684465b38d722ca9a3543b8af8568e6bad5cIssue Tracking, Patch, Third Party Advisory
- https://robotattack.org/Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20171222-0001/Issue Tracking, Third Party Advisory
- https://www.debian.org/security/2017/dsa-4072Issue Tracking, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00011.html
- http://www.kb.cert.org/vuls/id/144389Issue Tracking, Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/102195Third Party Advisory, VDB Entry
- https://github.com/bcgit/bc-java/commit/a00b684465b38d722ca9a3543b8af8568e6bad5cIssue Tracking, Patch, Third Party Advisory
- https://robotattack.org/Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20171222-0001/Issue Tracking, Third Party Advisory
- https://www.debian.org/security/2017/dsa-4072Issue Tracking, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.