CVE-2014-5270
Estado: ModificadaBaja (2.1)—
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 2.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.53%
- Percentil entre todas las CVEs puntuadas: 43
- Fecha de la puntuación: 2/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-200
Referencias
- http://lists.gnupg.org/pipermail/gnupg-announce/2014q3/000352.html
- http://openwall.com/lists/oss-security/2014/08/16/2
- http://www.cs.tau.ac.il/~tromer/handsoff/
- http://www.debian.org/security/2014/dsa-3024
- http://www.debian.org/security/2014/dsa-3073
- http://lists.gnupg.org/pipermail/gnupg-announce/2014q3/000352.html
- http://openwall.com/lists/oss-security/2014/08/16/2
- http://www.cs.tau.ac.il/~tromer/handsoff/
- http://www.debian.org/security/2014/dsa-3024
- http://www.debian.org/security/2014/dsa-3073
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-5270",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-10-10T01:55:10.383",
"references": [
{
"url": "http://lists.gnupg.org/pipermail/gnupg-announce/2014q3/000352.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://openwall.com/lists/oss-security/2014/08/16/2",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.cs.tau.ac.il/~tromer/handsoff/",
"tags": [
"Technical Description"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2014/dsa-3024",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2014/dsa-3073",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://lists.gnupg.org/pipermail/gnupg-announce/2014q3/000352.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://openwall.com/lists/oss-security/2014/08/16/2",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.cs.tau.ac.il/~tromer/handsoff/",
"tags": [
"Technical Description"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2014/dsa-3024",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2014/dsa-3073",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576."
},
{
"lang": "es",
"value": "Libgcrypt anterior a 1.5.4, utilizado en GnuPG y otros productos, no realiza debidamente la normalización y aleatorización de texto cifrado, lo que facilita a atacantes físicamente próximos realizar ataques de extracción de claves mediante el aprovechamiento de la habilidad de recoger datos de voltaje del metal expuesto, un vector deferente a CVE-2013-4576."
}
],
"lastModified": "2026-06-17T00:11:18.607",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B83822B-BC72-455D-A350-7DC9545E14A9",
"versionEndIncluding": "1.5.3"
},
{
"criteria": "cpe:2.3:a:gnupg:libgcrypt:1.4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7AE9E5CD-F6F8-4208-ACD2-5E2E88660A01"
},
{
"criteria": "cpe:2.3:a:gnupg:libgcrypt:1.4.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "128317AB-E441-47E3-BE5C-86C0D9C267E1"
},
{
"criteria": "cpe:2.3:a:gnupg:libgcrypt:1.4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5C7509E7-9DF3-42AC-A538-A1BE675253BF"
},
{
"criteria": "cpe:2.3:a:gnupg:libgcrypt:1.4.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FAFA68DC-FFA3-4538-8082-93588CCB44D7"
},
{
"criteria": "cpe:2.3:a:gnupg:libgcrypt:1.4.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5FEEF3D2-57D5-4E33-8856-B7A859ADD453"
},
{
"criteria": "cpe:2.3:a:gnupg:libgcrypt:1.5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "73E283C1-F1AE-4D29-A683-B5C5503133EC"
},
{
"criteria": "cpe:2.3:a:gnupg:libgcrypt:1.5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B7AEF669-B7AA-425A-988A-9F858937EC76"
},
{
"criteria": "cpe:2.3:a:gnupg:libgcrypt:1.5.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "67D0DD4C-9A2C-4B41-BA83-E7492EF8D434"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16F59A04-14CF-49E2-9973-645477EA09DA"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}