CVE-2017-13099: high-severity vulnerability in wolfSSL
wolfSSL Bleichenbacher/ROBOT
Published · Updated
Patch soon. It has a working public exploit.
wolfSSL versions before 3.12.2 have a weakness in how they handle RSA encryption during TLS connections, allowing attackers to gradually figure out the private key through repeated connection attempts. This is a serious flaw that can compromise the entire security of encrypted communications.
wolfSSL prior to 3.12.2 implements a weak Bleichenbacher oracle in RSA key exchange cipher suites, enabling padding oracle attacks (ROBOT). An attacker can exploit timing or error response differences to perform plaintext recovery and progressively derive the private key without authentication; impacts confidentiality of all TLS sessions using RSA key exchange.
In the same product, most dangerous first.