Inadequate RSA Padding

Inadequate RSA padding in C#

Description

PKCS#1 v1.5 padding for RSA encryption can expose a padding oracle if decryption errors or processing times reveal whether the padding is valid. Unpadded RSA is deterministic and vulnerable to ciphertext manipulation, so it is not a safe alternative.

Potential impact

  • Increased risk of ciphertext decryption, message forgery, and disclosure of sensitive information.

Remediation

Use OAEP padding and prefer RSAEncryptionPadding.OaepSHA256 or stronger supported options where possible.

Examples

Before

csharp
return rsa.Encrypt(data, RSAEncryptionPadding.Pkcs1);

After

csharp
return rsa.Encrypt(data, RSAEncryptionPadding.OaepSHA256);

Explanation:

  • Before: A padding oracle can arise if the decrypting system distinguishes padding errors when processing PKCS#1 v1.5 ciphertext.
  • After: Use OAEP padding, preferring RSAEncryptionPadding.OaepSHA256 or stronger options when supported.

References