PT-2025-27383 · Rlpx · Rlpx

CVE-2015-20112

·

Publicado

2025-06-29

·

Atualizado

2025-06-30

CVSS v3.1

3.4

Baixa

VetorAV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: RLPx version 5
Description: The issue concerns RLPx 5, which has two CTR streams based on the same key, IV, and nonce. This design flaw can facilitate decryption on a private network.
Recommendations: For RLPx version 5, consider reconfiguring the CTR streams to use distinct keys, IVs, and nonces to prevent potential decryption on private networks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-20112

Produtos afetados

Rlpx