CVE-2025-7383: Timing side-channel vulnerability in AES-CBC decryption with PKCS#7 padding in Oberon PSA Crypto library
Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 1.5.1 allows an attacker to recover plaintexts via timing measurements of AES-CBC PKCS#7 decrypt operations.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7383?
CVE-2025-7383 has a high severity due to its potential to allow attackers to recover plaintext from encrypted data.
How do I fix CVE-2025-7383?
To fix CVE-2025-7383, upgrade the Oberon PSA Crypto library to version 1.5.1 or later.
What specific versions are affected by CVE-2025-7383?
CVE-2025-7383 affects all versions of the Oberon PSA Crypto library from 1.0.0 up to, but not including, 1.5.1.
What type of attack does CVE-2025-7383 allow?
CVE-2025-7383 allows a padding oracle attack that can exploit timing measurements during AES-CBC PKCS#7 decrypt operations.
Who is affected by CVE-2025-7383?
Users and developers utilizing the Oberon PSA Crypto library within the specified version range are affected by CVE-2025-7383.