Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
响应差异性信息暴露
Vulnerability Title
Eclipse Milo 信息泄露漏洞
Vulnerability Description
Eclipse Milo是美国Eclipse基金会开源的一个实现OPCUA协议的通信栈库。 Eclipse Milo 0.6.0版本至1.1.4版本存在侧信道信息泄露漏洞,该漏洞源于用户名令牌处理对无效RSA PKCS#1 v1.5填充和其他身份验证失败返回可区分的错误,可能导致中间人攻击者利用填充预言机恢复受害者的密码并成功认证。
CVSS Information
N/A
Vulnerability Type
N/A