Use of RSA Algorithm without OAEP Affecting upydev package, versions [0,]
Threat Intelligence
EPSS
0.07% (31st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-UPYDEV-6070117
- published 21 Nov 2023
- disclosed 20 Nov 2023
- credit gxx777
Introduced: 20 Nov 2023
CVE-2023-48051 Open this link in a new tabHow to fix?
There is no fixed version for upydev
.
Overview
upydev is a Command line tool for MicroPython devices
Affected versions of this package are vulnerable to Use of RSA Algorithm without OAEP due to outdated padding of the encryption and signature verification in keygen.py
file. An attacker can decrypt sensitive information.
References
CVSS Scores
version 3.1