CWE-780Variant

Use of RSA Algorithm without OAEP

Incomplete in the CWE catalog · 3 CVEs mapped

3
CVEs mapped
5.9
Median CVSS
What it is

The product uses the RSA algorithm but does not incorporate Optimal Asymmetric Encryption Padding (OAEP), which might weaken the encryption.

Recent examples
2.3cvss
CVE-2025-9071

Insecure RSA-OAEP implementation with all-zero seed for padding in Oberon PSA Crypto

Erroneously using an all-zero seed for RSA-OEAP padding instead of the generated random bytes, in Oberon microsystems AG’s Oberon PSA Crypto library in all versions up to 1.5.1, results in deterministic RSA and thus in a loss of confidentiality for guessable messages, recognition of repeated messages, and loss of security proofs.

LOWno explanation yet
0%
epss
5.9cvss
CVE-2024-51456

IBM Robotic Process Automation information disclosure

IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obtain sensitive data that may be exposed through certain crypto-analytic attacks.

MEDIUMno explanation yet
0%
epss
7.7cvss
CVE-2022-40722

Misconfiguration of RSA padding for offline MFA in the PingID Adapter for PingFederate.

A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-780
Abstraction
Variant
Structure
Simple
Status
Incomplete
References (2)