Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2017-13091— The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), including improperly specified padding in CBC mode allows use of an EDA tool as a decryption oracle

Quick assessment

Affected
IEEE Standard
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

IEEE P1735是一个专门用来加密电子设计的知识产权的标准。 IEEE P1735的实现存在加密问题漏洞。本地攻击者可利用该漏洞获取电子设计的知识产权信息。

AI Predicted 7.5 Difficulty: Moderate EPSS 0.46% · P37

Possible ATT&CK Techniques 1 AI

T1527
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2017-13091

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), including improperly specified padding in CBC mode allows use of an EDA tool as a decryption oracle
Source: CVE Program / CVE List V5
Vulnerability Description
The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including improperly specified padding in CBC mode allows use of an EDA tool as a decryption oracle. The methods are flawed and, in the most egregious cases, enable attack vectors that allow recovery of the entire underlying plaintext IP. Implementations of IEEE P1735 may be weak to cryptographic attacks that allow an attacker to obtain plaintext intellectual property without the key, among other impacts.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
加密问题
Source: CVE Program / CVE List V5
Vulnerability Title
IEEE P1735 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IEEE P1735是一个专门用来加密电子设计的知识产权的标准。 IEEE P1735的实现存在加密问题漏洞。本地攻击者可利用该漏洞获取电子设计的知识产权信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
IEEE Standard P1735 -

II. Public POCs for CVE-2017-13091

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-13091

请登录查看更多情报信息。

Vendor Advisories for CVE-2017-13091 (2)

Same Patch Batch · IEEE · 2018-07-13 · 7 CVEs total

CVE-2017-13092 The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellec
CVE-2017-13093 The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellec
CVE-2017-13094 The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellec
CVE-2017-13095 The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellec
CVE-2017-13096 The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellec
CVE-2017-13097 The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellec

IV. Related Vulnerabilities

V. Comments for CVE-2017-13091

No comments yet


Leave a comment