CVE-2020-28052 - CVE House
Back to Database
Status published High CVE-2020-28052

An issue was discovered in Legion of the Bouncy Castle...

Vulnerability Description

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-28052

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

bouncycastle

View all reports →

Affected Software

bc-java, karaf, banking corporate lending process management, banking credit facilities process management, banking extensibility workbench, banking supply chain finance, banking virtual account management, blockchain platform, commerce guided search, communications application session controller, communications cloud native core network slice selection function, communications convergence, communications pricing design center, communications session report manager, communications session route manager, jd edwards enterpriseone tools, peoplesoft enterprise peopletools, utilities framework, webcenter portal, communications messaging server
Vulnerable Versions:
1.65, 1.66, 4.3.2, 14.2.0, 14.3.0, 14.5.0, 0, 11.3.2, 3.9m0p3, 1.2.1, 3.0.2.2.0, 12.0.0.3.0, 8.0.0, 8.2.0, 8.56, 8.57, 8.58, 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0, 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0, 8.0.2, 8.1

Timeline

Official Publish: December 18th, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.