Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-4574

Опубликовано: 27 окт. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

PolarSSL versions prior to v1.1 use the HAVEGE random number generation algorithm. At its heart, this uses timing information based on the processor's high resolution timer (the RDTSC instruction). This instruction can be virtualized, and some virtual machine hosts have chosen to disable this instruction, returning 0s or predictable results.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:polarssl:polarssl:*:*:*:*:*:*:*:*
Версия до 1.1.0 (исключая)

EPSS

Процентиль: 62%
0.00433
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-338

Связанные уязвимости

CVSS3: 9.8
debian
больше 4 лет назад

PolarSSL versions prior to v1.1 use the HAVEGE random number generatio ...

github
почти 4 года назад

PolarSSL versions prior to v1.1 use the HAVEGE random number generation algorithm. At its heart, this uses timing information based on the processor's high resolution timer (the RDTSC instruction). This instruction can be virtualized, and some virtual machine hosts have chosen to disable this instruction, returning 0s or predictable results.

EPSS

Процентиль: 62%
0.00433
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-338