- Description
- SSH Tectia Client/Server/Connector 5.1.0 and earlier, Manager 2.2.0 and earlier, and other products, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents Tectia from correctly verifying X.509 and other certificates that use PKCS #1, a similar issue to CVE-2006-4339.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:N
- Hype score
- Not currently trending
- Comment
- -
- Impact
- -
- Solution
- -
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ssh:tectia_client:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2E317E29-0436-4DE5-BEAE-360919F81533",
"versionEndIncluding": "5.1.0"
},
{
"criteria": "cpe:2.3:a:ssh:tectia_connector:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD202BF8-1A73-44DA-93FB-DA21A7825B93",
"versionEndIncluding": "5.1.0"
},
{
"criteria": "cpe:2.3:a:ssh:tectia_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "821AFCAC-3769-4891-B62C-042803023BB7",
"versionEndIncluding": "2.2.0"
},
{
"criteria": "cpe:2.3:a:ssh:tectia_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F63849B9-02E1-4361-9686-8C90C7ADDA72",
"versionEndIncluding": "5.1.0"
}
],
"operator": "OR"
}
]
}
]