A Padding Oracle exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). Under an MITM condition within the OSCI infrastructure, an attacker needs to send crafted protocol messages to analyse the CBC mode padding in order to decrypt the transport encryption.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2017/Jun/44 | Mailing List Third Party Advisory |
http://blog.sec-consult.com/2017/06/german-e-government-details-vulnerabilities.html | Technical Description Third Party Advisory |
http://seclists.org/fulldisclosure/2017/Jun/44 | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:06
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2017/Jun/44 - Mailing List, Third Party Advisory |
Information
Published : 2017-06-30 12:29
Updated : 2024-11-21 03:06
NVD link : CVE-2017-10668
Mitre link : CVE-2017-10668
CVE.ORG link : CVE-2017-10668
JSON object : View
Products Affected
xoev
- osci_transport_library
CWE
CWE-327
Use of a Broken or Risky Cryptographic Algorithm