A Padding Oracle exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). Under an MITM condition within the OSCI infrastructure, an attacker needs to send crafted protocol messages to analyse the CBC mode padding in order to decrypt the transport encryption.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2017/Jun/44 | Mailing List Third Party Advisory |
http://blog.sec-consult.com/2017/06/german-e-government-details-vulnerabilities.html | Technical Description Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-06-30 05:29
Updated : 2019-10-02 17:03
NVD link : CVE-2017-10668
Mitre link : CVE-2017-10668
JSON object : View
CWE
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
Products Affected
xoev
- osci_transport_library