PT-2026-71406 · Unknown · Oberon Psa Crypto
CVE-2026-16459
·
Published
2026-08-13
·
Updated
2026-08-13
CVSS v4.0
5.9
Medium
| Vector | AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Oberon PSA Crypto versions 1.0.0 through 2.1.0
Description
A padding oracle attack exists in the Oberon PSA Crypto library. This issue allows an attacker to recover plaintexts by performing timing measurements of RSA PKCS#1 v1.5 decrypt operations. A padding oracle attack is a side-channel attack where an attacker can deduce the contents of encrypted data by observing the errors or timing differences produced by the system when processing incorrectly padded data.
Recommendations
Update Oberon PSA Crypto to version 2.1.1.
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oberon Psa Crypto