---
id: CVE-2020-20949
title: >-
  Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic
  firmware library software expansion for STM32Cube (UM1924)
summary: >-
  Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic
  firmware library software expansion for STM32Cube (UM1924). The vulnerability
  can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted
  ciph…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-327
vendor: st
product: stm32cubef0
affected:
  - stm32cubef0
  - stm32cubef1
  - stm32cubef2
  - stm32cubef3
  - stm32cubef4
  - stm32cubef7
  - stm32cubeg0
  - stm32cubeg4
  - stm32cubeh7
  - stm32cubeide
  - stm32cubel0
  - stm32cubel1
  - stm32cubel4
  - stm32cubel4+
  - stm32cubel5
  - stm32cubemonitor
  - stm32cubemp1
  - stm32cubemx
  - stm32cubeprogrammer
  - stm32cubewb
  - stm32cubewl
  - public_key_cryptography_standards_#1 = 1.5
published: '2021-01-20'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-20949'
references:
  - url: 'http://archiv.infsec.ethz.ch/education/fs08/secsem/bleichenbacher98.pdf'
    label: cve@mitre.org
  - url: 'http://x-cube-cryptolib.com'
    label: cve@mitre.org
  - url: >-
      https://bi-zone.medium.com/silence-will-fall-or-how-it-can-take-2-years-to-get-your-vuln-registered-e6134846f5bb
    label: cve@mitre.org
  - url: 'https://www.st.com/en/embedded-software/x-cube-cryptolib.html'
    label: cve@mitre.org
  - url: 'http://archiv.infsec.ethz.ch/education/fs08/secsem/bleichenbacher98.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://st.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://x-cube-cryptolib.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://bi-zone.medium.com/silence-will-fall-or-how-it-can-take-2-years-to-get-your-vuln-registered-e6134846f5bb
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.st.com/en/embedded-software/x-cube-cryptolib.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00926
epssPercentile: 0.5879
ingestedAt: '2026-07-05T00:59:25.798Z'
---

## Overview

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.

## Affected

- `stm32cubef0`
- `stm32cubef1`
- `stm32cubef2`
- `stm32cubef3`
- `stm32cubef4`
- `stm32cubef7`
- `stm32cubeg0`
- `stm32cubeg4`
- `stm32cubeh7`
- `stm32cubeide`
- `stm32cubel0`
- `stm32cubel1`
- `stm32cubel4`
- `stm32cubel4+`
- `stm32cubel5`
- `stm32cubemonitor`
- `stm32cubemp1`
- `stm32cubemx`
- `stm32cubeprogrammer`
- `stm32cubewb`
- `stm32cubewl`
- `public_key_cryptography_standards_#1 = 1.5`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
