TROYANOSYVIRUS
Volver a CVEs

CVE-2023-0361

HIGH
7.4

Descripcion

A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.

Detalles CVE

Puntuacion CVSS v3.17.4
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vector de ataqueNETWORK
ComplejidadHIGH
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado2/15/2023
Ultima modificacion3/19/2025
Fuentenvd
Avistamientos honeypot0

Productos afectados

debian:debian_linuxfedoraproject:fedoragnu:gnutlsnetapp:active_iq_unified_managernetapp:converged_systems_advisor_agentnetapp:ontap_select_deploy_administration_utilityredhat:enterprise_linux

Debilidades (CWE)

CWE-203CWE-203

Referencias

https://access.redhat.com/security/cve/CVE-2023-0361(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/tlsfuzzer/tlsfuzzer/pull/679(af854a3a-2127-422b-91ae-364da2661108)
https://gitlab.com/gnutls/gnutls/-/issues/1050(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20230324-0005/(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20230725-0005/(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.