A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array is indexed with bits derived from a secret key.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Sep 26, 2017 | |
| Debian | debian-upgrade-botan1-10 | Feb 25, 2019 | Sep 25, 2017 | |
| Suse | — | suse-upgrade-libbotan-1_10-0suse-upgrade-libbotan-devel | Oct 26, 2017 | Sep 25, 2017 |
| Ubuntu | ubuntu-pro-upgrade-botan1-10 | Nov 19, 2024 | Sep 26, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub