← Back

CVE-2023-0361

nvd nist
Published: Feb 15, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.2 / Impact: 5.2
Source: NVD

Description

A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.

Affected (10)

Products: Gnu: Gnutls · Redhat: Enterprise Linux · Debian: Debian Linux · +2 more
Show all products
1 product
Gnutls
1 product
Enterprise Linux
1 product
Debian Linux
1 product
Fedora
3 products
Active Iq Unified Manager
Converged Systems Advisor Agent
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.6.8-11.el8_2
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 8.0
Version 9.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 36
Version 37
Version 38
Configuration E
3 vulnerable

References (18)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingPatch
Source: secalert@redhat.com
ExploitIssue TrackingVendor Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.