CVE-2023-33850

IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:txseries_for_multiplatform:8.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:txseries_for_multiplatform:9.1:*:*:*:*:*:*:*
OR cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:ibm:txseries_for_multiplatform:8.2:*:*:*:*:*:*:*
OR cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:ibm:cics_tx:11.1:*:*:*:standard:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:a:ibm:cics_tx:10.1:*:*:*:advanced:*:*:*
cpe:2.3:a:ibm:cics_tx:11.1:*:*:*:advanced:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

27 Sep 2024, 14:15

Type Values Removed Values Added
Summary (en) IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 257132. (en) IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information.
References
  • {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/257132', 'tags': ['VDB Entry', 'Vendor Advisory'], 'source': 'psirt@us.ibm.com'}

19 Sep 2024, 16:15

Type Values Removed Values Added
Summary (en) IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 257132. (en) IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 257132.

28 Aug 2023, 19:51

Type Values Removed Values Added
CWE CWE-203
First Time Linux
Hp hp-ux
Hp
Ibm cics Tx
Ibm aix
Microsoft
Ibm
Ibm txseries For Multiplatform
Microsoft windows
Linux linux Kernel
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:ibm:cics_tx:11.1:*:*:*:standard:*:*:*
cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:txseries_for_multiplatform:9.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:txseries_for_multiplatform:8.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:txseries_for_multiplatform:8.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cics_tx:10.1:*:*:*:advanced:*:*:*
cpe:2.3:a:ibm:cics_tx:11.1:*:*:*:advanced:*:*:*
References (MISC) https://www.ibm.com/support/pages/node/7010369 - (MISC) https://www.ibm.com/support/pages/node/7010369 - Vendor Advisory
References (MISC) https://www.ibm.com/support/pages/node/7022414 - (MISC) https://www.ibm.com/support/pages/node/7022414 - Vendor Advisory
References (MISC) https://www.ibm.com/support/pages/node/7022413 - (MISC) https://www.ibm.com/support/pages/node/7022413 - Vendor Advisory
References (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/257132 - (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/257132 - VDB Entry, Vendor Advisory

22 Aug 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-22 21:15

Updated : 2024-09-27 14:15


NVD link : CVE-2023-33850

Mitre link : CVE-2023-33850

CVE.ORG link : CVE-2023-33850


JSON object : View

Products Affected

hp

  • hp-ux

ibm

  • aix
  • cics_tx
  • txseries_for_multiplatform

linux

  • linux_kernel

microsoft

  • windows
CWE
CWE-203

Observable Discrepancy