← Back

CVE-2013-1624

nvd nist
Published: Feb 8, 2013Modified: Apr 29, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:H/Au:N/C:P/I:P/A:N
Exploitability: 4.9 / Impact: 4.9
Source: NVD

Description

The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

Affected (56)

2 products
Bc Java
Configuration A
47 vulnerable
Vulnerable SoftwareAffected Versions
Bouncycastle
Version 1.01
Version 1.02
Version 1.03
Version 1.04
Version 1.05
Version 1.06
Version 1.07
Version 1.08
Version 1.09
Version 1.10
Version 1.11
Version 1.12
Version 1.13
Version 1.14
Version 1.15
Version 1.16
Version 1.17
Version 1.18
Version 1.19
Version 1.20
Version 1.21
Version 1.22
Version 1.23
Version 1.24
Version 1.25
Version 1.26
Version 1.27
Version 1.28
Version 1.29
Version 1.30
Version 1.31
Version 1.32
Version 1.33
Version 1.34
Version 1.35
Version 1.36
Version 1.37
Version 1.38
Version 1.39
Version 1.40
Version 1.41
Version 1.42
Version 1.43
Version 1.44
Version 1.45
Version 1.46
Version 1.47
Configuration B
9 vulnerable

Related CWEs

References (12)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.