CNNVD-202508-3589 Information

CNNVD ID

CNNVD-202508-3589

CVE-2025-7071

  • CNNVD Published: 2025-08-29

Description (Chinese)

Oberon microsystem AG ocrypto library是瑞士Oberon公司的一个加密软件库。 Oberon microsystem AG ocrypto library 3.1.0至3.9.2之前版本存在安全漏洞,该漏洞源于AES-CBC PKCS#7解密操作存在填充预言攻击。

Description (English)

Oberon Microsystem AG ocrypto library is an encryption software library of Oberon, Switzerland. There was a security loophole in previous versions of Oberon Microsystem AG ocrypto library 3.1.0 to 3.9.2, which originated from the predicated attack of the AES-CBC PKCS#7 decryption operation.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Oberon

Published

2025-08-29

Last Modified

2026-02-24

References

https://www.oberon.ch/security-advisories/cve-2025-7071/ https://access.redhat.com/security/cve/cve-2025-7071 https://nvd.nist.gov/vuln/detail/CVE-2025-7071

Patch

https://www.oberon.ch/products/ocrypto/

Share on: