Tag
medium
advisory
Hitachi Energy GMS600 Vulnerable to Bleichenbacher Attack via CVE-2022-4304
2 rules 1 TTP 1 CVEHitachi Energy GMS600 versions 1.3.0 and 1.3.1 are affected by CVE-2022-4304, a vulnerability in the OpenSSL RSA Decryption implementation; an attacker could exploit this timing-based side channel to recover plaintext across a network in a Bleichenbacher-style attack by sending trial messages to the server and recording processing times, eventually decrypting application data.
GMS600 versions 1.3.0 and 1.3.1
bleichenbacher
timing attack
openssl
critical infrastructure
2r
1t
1c
high
advisory
Forge RSA Signature Forgery Vulnerability
2 rules 1 TTP 2 CVEsForge is vulnerable to signature forgery in RSA-PKCS due to ASN.1 extra field, allowing attackers to forge signatures by stuffing garbage bytes within the ASN structure for low public exponent keys (e=3), enabling Bleichenbacher style forgery and affecting npm/node-forge versions less than 1.4.0.
node-forge
forge
rsa
signature-forgery
bleichenbacher
2r
1t
2c
updated