CVE-2020-20949: Medium severity ST Stm32cubef0 vulnerability
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-20949?
CVE-2020-20949 is a vulnerability known as Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924).
How does the Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA work?
Bleichenbacher's attack allows an attacker to decrypt an encrypted ciphertext by making successive queries using Bleichenbacher's oracle attack.
What is the severity of CVE-2020-20949?
The severity of CVE-2020-20949 is medium with a severity value of 5.9.
Which software and devices are affected by CVE-2020-20949?
The vulnerability affects STM32Cube firmware library software expansions for various STM32 devices, including Stm32cubef0, Stm32cubef1, Stm32cubef2, Stm32cubef3, Stm32cubef4, Stm32cubef7, Stm32cubeg0, Stm32cubeg4, Stm32cubeh7, Stm32cubeide, Stm32cubel0, Stm32cubel1, Stm32cubel4, Stm32cubel4+, Stm32cubel5, Stm32cubemonitor, Stm32cubemp1, Stm32cubemx, Stm32cubeprogrammer, Stm32cubewb, Stm32cubewl.
How can I fix CVE-2020-20949?
To fix CVE-2020-20949, users are advised to update the STM32Cube firmware library software expansion to the latest version provided by STMicroelectronics.