CVE-2020-11713: High severity wolfssl wolfmqtt vulnerability
Published Apr 12, 2020
·Updated
wolfSSL 4.3.0 has mulmod code in wceccmulmodex in ecc.c that does not properly resist timing side-channel attacks.
Affected Software
1 affected component
wolfSSL wolfssl=4.3.0
Remediation
Patch Available
Event History
Apr 12, 2020
CVE Published
via MITRE·04:54 PM
Data Sourced
via MITRE·04:54 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this wolfSSL vulnerability?
CVE-2020-11713
2
What is the severity level of CVE-2020-11713?
The severity level of CVE-2020-11713 is high with a score of 7.5.
3
What is the affected version of wolfSSL?
The affected version of wolfSSL is 4.3.0.
4
What is the CWE number for this vulnerability?
The CWE number for this vulnerability is CWE-203.
5
How can I fix CVE-2020-11713 in wolfSSL?
To fix CVE-2020-11713 in wolfSSL, it is recommended to update to a version higher than 4.3.0.