CVE-2019-3740
⚪ Do wiadomości
Wykrycie różnic czasowych w RSA BSAFE Crypto-J umożliwia zdalne odzyskanie kluczy DSA.
CVSS
6.5
EPSS
3.8%
Exploit
none
Vendor
oracle
Opis źródłowy (NVD)
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 3.8% |
| Opublikowano (NVD) | 2019-09-18 23:15:11 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:16:54 UTC |
Referencje
- https://www.dell.com/support/security/en-us/details/DOC-106556/DSA-2019-094-RSA-BSAFE®%3B-Crypto-J-Multiple-Security-Vulnerabilities ([email protected])
- https://www.oracle.com//security-alerts/cpujul2021.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpuApr2021.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpuapr2022.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpujul2020.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpuoct2020.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpuoct2021.html ([email protected]) [Patch, Third Party Advisory]