BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable application. This vulnerability is referred to as "ROBOT."
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos Cx | aruba-aos-cx-cve-2017-13098 | Feb 24, 2025 | Feb 22, 2022 | |
| Debian | debian-upgrade-bouncycastle | Dec 22, 2017 | Dec 12, 2017 | |
| Freebsd | freebsd-upgrade-package-bouncycastlefreebsd-upgrade-package-bouncycastle15 | Dec 31, 2017 | Dec 29, 2017 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-runtime-erlang-21-0-11-4-6-0-1-1-0oracle-solaris-11-4-upgrade-runtime-erlang-documentation-21-0-11-4-6-0-1-1-0 | Feb 20, 2019 | Dec 12, 2017 | |
| Suse | — | suse-upgrade-bouncycastlesuse-upgrade-bouncycastle-javadocsuse-upgrade-bouncycastle-pg | Jun 16, 2018 | Dec 12, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub