CVE-2025-7071
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-08-29
Last updated on: 2025-08-29
Assigner: Switzerland Government Common Vulnerability Program
Description
Description
Padding oracle attack vulnerability in Oberon microsystem AGβs ocrypto library in all versions since 3.1.0 and prior to 3.9.2 allows an attacker to recover plaintexts via timing measurements of AES-CBC PKCS#7 decrypt operations.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| oberon_microsystem_ag | ocrypto | 3.9.1 |
| oberon_microsystem_ag | ocrypto | 3.1.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-208 | Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not. |
| CWE-327 | The product uses a broken or risky cryptographic algorithm or protocol. |