Vulnerabilità · 131 giorni fa

Le sessioni TLS di GMS600 esposte a rischio di decrittazione

Il problema non è l'esecuzione di codice in GMS600. È un side channel temporale nel componente OpenSSL che può consentire a un attaccante di recuperare il pre-master secret TLS e leggere i dati applicativi inviati sulla connessione.

CVE-2022-4304

NVD KEV

CVSS 5.9 MEDIUM: a timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. EPSS 16% (97º percentile), in aumento rispetto a 0.2%.

Cronologia

Fonti

1 fonte che coprono questa storia

Entità

Part of the PlainSec briefing for 2026-05-21

Editions

Storie correlate