Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-13099

Опубликовано: 13 дек. 2017
Источник: debian
EPSS Высокий

Описание

wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is referred to as "ROBOT."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wolfsslfixed3.13.0+dfsg-1package

Примечания

  • https://github.com/wolfSSL/wolfssl/pull/1229

  • https://robotattack.org/

EPSS

Процентиль: 99%
0.70023
Высокий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is referred to as "ROBOT."

CVSS3: 7.5
nvd
около 8 лет назад

wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is referred to as "ROBOT."

CVSS3: 5.9
github
больше 3 лет назад

wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is referred to as "ROBOT."

EPSS

Процентиль: 99%
0.70023
Высокий