---
id: CVE-2020-20950
title: >-
  Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries
  for Applications 2018-11-26 All up to 2018-11-26
summary: >-
  Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries
  for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow
  one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext
  by …
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-327
vendor: ietf
product: public_key_cryptography_standards_#1
affected:
  - public_key_cryptography_standards_#1 = 1.5
  - microchip_libraries_for_applications <= 2018-11-26
published: '2021-01-19'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-20950'
references:
  - url: 'http://archiv.infsec.ethz.ch/education/fs08/secsem/bleichenbacher98.pdf'
    label: cve@mitre.org
  - url: >-
      https://bi-zone.medium.com/silence-will-fall-or-how-it-can-take-2-years-to-get-your-vuln-registered-e6134846f5bb
    label: cve@mitre.org
  - url: 'https://www.microchip.com/mplab/microchip-libraries-for-applications'
    label: cve@mitre.org
  - url: 'http://archiv.infsec.ethz.ch/education/fs08/secsem/bleichenbacher98.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://microchip.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://bi-zone.medium.com/silence-will-fall-or-how-it-can-take-2-years-to-get-your-vuln-registered-e6134846f5bb
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.microchip.com/mplab/microchip-libraries-for-applications'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00866
epssPercentile: 0.56902
ingestedAt: '2026-07-05T00:59:25.793Z'
---

## Overview

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.

## Affected

- `public_key_cryptography_standards_#1 = 1.5`
- `microchip_libraries_for_applications <= 2018-11-26`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
