CVE-2017-13098 REJECTED

BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable application. This vulnerability is referred to as "ROBOT."

EPSS 66.23% · 98.5th percentile

Risk Scores

EPSS Score
66.23%
98.5th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSbouncycastle0, 1.57-1, 1.58-1

Timeline

References

Open in Interactive Console →