CVSS v3
7.5
HIGH
EPSS Score
1.0 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.
Technical details
- Published
- 2024-01-16
Frequently asked questions
What is CVE-2024-0553?
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.
Is CVE-2024-0553 actively exploited?
Active exploitation of CVE-2024-0553 has not been confirmed. The EPSS score is 1.0%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2024-0553?
CVE-2024-0553 has a CVSS v3 base score of 7.5 (HIGH severity).
Is CVE-2024-0553 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2024 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).