We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2015-20112



Description

RLPx 5 has two CTR streams based on the same key, IV, and nonce. This can facilitate decryption on a private network.

Reserved 2025-06-29 | Published 2025-06-29 | Updated 2025-06-29 | Assigner mitre


LOW: 3.4CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N

Problem types

CWE-325 Missing Cryptographic Step

Product status

Default status
unknown

5
affected

References

github.com/hyperledger/besu/issues/7926

github.com/ethereum/go-ethereum/issues/1315

github.com/ethereum/devp2p/blob/master/rlpx.md

github.com/...ommit/e8cba7283b57280b1bcf5761478f852398365901

github.com/ethereum/devp2p/issues/32

cve.org (CVE-2015-20112)

nvd.nist.gov (CVE-2015-20112)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2015-20112

Support options

Helpdesk Chat, Email, Knowledgebase