CVE-2023-5388: Medium severity F5 F5OS-A vulnerability
It was discovered that the numerical library used in NSS for RSA cryptography leaks information whether high order bits of the RSA decryption result are zero. This information can be used to mount a Bleichenbacher or Manger like attack against all RSA decryption operations. As the leak happens before any padding operations, it affects all padding modes: PKCS#1 v1.5, OAEP, and RSASVP. Both API level calls and TLS server operation are affected.
References: https://people.redhat.com/~hkario/marvin/
Other sources
NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data.
— Mozilla
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-5388?
CVE-2023-5388 has a critical severity rating due to its potential to allow information leakage that may lead to further attacks.
How do I fix CVE-2023-5388?
To fix CVE-2023-5388, users should update affected software to the latest patched versions, which include Mozilla Firefox, Firefox ESR, Thunderbird, and specific IBM Cognos Analytics versions.
What types of software are affected by CVE-2023-5388?
CVE-2023-5388 affects Mozilla Firefox, Firefox ESR, Thunderbird, and specific versions of IBM Cognos Analytics as well as certain configurations of F5 products.
What attack methods are enabled by CVE-2023-5388?
CVE-2023-5388 enables attackers to potentially exploit RSA decryption operations using techniques similar to Bleichenbacher or Manger attacks.
When was CVE-2023-5388 disclosed?
CVE-2023-5388 was disclosed in 2024, following the identification of the vulnerability in the NSS numerical library.