CVE-2020-25658
Timing attacks in python-rsa
5.9
MEDIUM
CVSS 3.1
EPSS 1.6%
Description
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.
How to fix CVE-2020-25658
To remediate CVE-2020-25658, upgrade the affected package to a fixed version below.
- Debian/python-rsa—no fix listed
- PyPI/rsa—upgrade to 4.7 or later
- —upgrade to 4.7 or later
Is CVE-2020-25658 being exploited?
Low — EPSS is 1.6%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0
- >= 2.1, < 4.7
- >= 2.1, < 4.7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |