CVE-2017-13099: wolfSSL Bleichenbacher/ROBOT
Published Dec 13, 2017
·Updated
wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is referred to as "ROBOT."
Affected Software
4 affected components
wolfSSL wolfssl<3.12.2
Siemens Scalance W1750d Firmware<8.3.0.1
Siemens SCALANCE W1750D
Arubanetworks Instant<6.5.4.6
Remediation
Patch Available
Event History
Dec 13, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-13099.
2
What is the severity of CVE-2017-13099?
The severity of CVE-2017-13099 is high.
3
Which software versions are affected by CVE-2017-13099?
wolfSSL prior to version 3.12.2 and Arubanetworks Instant prior to version 6.5.4.6 are affected by CVE-2017-13099.
4
What is the vulnerability referred to as?
The vulnerability is referred to as "ROBOT".
5
How can an attacker exploit CVE-2017-13099?
An attacker can recover the private key from a vulnerable wolfSSL application.