CVE-2023-50781

MEDIUM5.9EPSS 0.44%

m2crypto Bleichenbacher timing attack - incomplete fix for CVE-2020-25657

Published: 2/5/2024Modified: 2/28/2026
Also known as:GHSA-944j-8ch6-rf6x

Description

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

References (6)