Medium severity5.9NVD Advisory· Published Jun 30, 2017· Updated May 13, 2026
CVE-2017-10668
CVE-2017-10668
Description
A Padding Oracle exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). Under an MITM condition within the OSCI infrastructure, an attacker needs to send crafted protocol messages to analyse the CBC mode padding in order to decrypt the transport encryption.
Affected products
2cpe:2.3:a:xoev:osci_transport_library:1.6.1:*:*:*:java:*:*:*+ 1 more
- cpe:2.3:a:xoev:osci_transport_library:1.6.1:*:*:*:java:*:*:*
- cpe:2.3:a:xoev:osci_transport_library:1.6:*:*:*:.net:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- blog.sec-consult.com/2017/06/german-e-government-details-vulnerabilities.htmlnvdTechnical DescriptionThird Party Advisory
- seclists.org/fulldisclosure/2017/Jun/44nvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.