2017-12-13 02:29:00 2019-10-10 01:23:24

BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable application. This vulnerability is referred to as "ROBOT."

Vector

NETWORK

Complexity

MEDIUM

Authentication

NONE

Confidentiality

PARTIAL

Integrity

NONE

Availability

NONE
Bouncycastle Legion-of-the-bouncy-castle-java-crytography-api 1.55 (not an official CPE) Bouncycastle Legion-of-the-bouncy-castle-java-crytography-api 1.54 (not an official CPE) Bouncycastle Legion-of-the-bouncy-castle-java-crytography-api 1.53 (not an official CPE) Bouncycastle Legion-of-the-bouncy-castle-java-crytography-api 1.52 (not an official CPE) Bouncycastle Legion-of-the-bouncy-castle-java-crytography-api 1.51 (not an official CPE) Bouncycastle Legion-of-the-bouncy-castle-java-crytography-api 1.50 (not an official CPE) Bouncycastle Legion-of-the-bouncy-castle-java-crytography-api 1.49 (not an official CPE) Legion of the Bouncy Castle Java Cryptography API 1.48 Legion of the Bouncy Castle Java Cryptography API 1.47 Legion of the Bouncy Castle Java Cryptography API 1.46 Legion of the Bouncy Castle Java Cryptography API 1.45 Legion of the Bouncy Castle Java Cryptography API 1.44 Legion of the Bouncy Castle Java Cryptography API 1.43 Legion of the Bouncy Castle Java Cryptography API 1.42 Legion of the Bouncy Castle Java Cryptography API 1.41 Legion of the Bouncy Castle Java Cryptography API 1.40 Legion of the Bouncy Castle Java Cryptography API 1.39 Legion of the Bouncy Castle Java Cryptography API 1.38 Legion of the Bouncy Castle Java Cryptograph API 1.37 Legion of the Bouncy Castle Java Cryptography API 1.36 Legion of the Bouncy Castle Java Cryptography API 1.35 Legion of the Bouncy Castle Java Cryptography API 1.34 Legion of the Bouncy Castle Java Cryptography API 1.33 Legion of the Bouncy Castle Java Cryptography API 1.32 Legion of the Bouncy Castle Java Cryptography API 1.31 Legion of the Bouncy Castle Java Cryptography API 1.30 Legion of the Bouncy Castle Java Cryptography API 1.29 Legion of the Bouncy Castle Java Cryptography API 1.28 Legion of the Bouncy Castle Java Cryptography API 1.27 Legion of the Bouncy Castle Java Cryptography API 1.26 Legion of the Bouncy Castle Java Cryptography API 1.25 Legion of the Bouncy Castle Java Cryptography API 1.24 Legion of the Bouncy Castle Java Cryptography API 1.23 Legion of the Bouncy Castle Java Cryptography API 1.22 Legion of the Bouncy Castle Java Cryptography API 1.21 Legion of the Bouncy Castle Java Cryptography API 1.20 Legion of the Bouncy Castle Java Cryptography API 1.19 Legion of the Bouncy Castle Java Cryptography API 1.18 Legion of the Bouncy Castle Java Cryptography API 1.17 Legion of the Bouncy Castle Java Cryptography API 1.16 Legion of the Bouncy Castle Java Cryptography API 1.15 Legion of the Bouncy Castle Java Cryptography API 1.14 Legion of the Bouncy Castle Java Cryptography API 1.13 Legion of the Bouncy Castle Java Cryptography API 1.12 Legion of the Bouncy Castle Java Cryptography API 1.11 Legion of the Bouncy Castle Java Cryptography API 1.10 Legion of the Bouncy Castle Java Cryptography API 1.08 Legion of the Bouncy Castle Java Cryptography API 1.09 Legion of the Bouncy Castle Java Cryptography API 1.07 Legion of the Bouncy Castle Java Cryptography API 1.06 Legion of the Bouncy Castle Java Cryptography API 1.05 Legion of the Bouncy Castle Java Cryptography API 1.04 Legion of the Bouncy Castle Java Cryptography API 1.03 Legion of the Bouncy Castle Java Cryptography API 1.02 Legion of the Bouncy Castle Java Cryptography API 1.01 Bouncycastle Legion-of-the-bouncy-castle-java-crytography-api 1.56 (not an official CPE) Bouncycastle Legion-of-the-bouncy-castle-java-crytography-api 1.57 (not an official CPE) Bouncycastle Legion-of-the-bouncy-castle-java-crytography-api 1.58 (not an official CPE)