CVE-2024-1545: Fault Injection of RSA encryption in WolfCrypt
Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges via Rowhammer fault injection to the RsaKey structure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1545?
CVE-2024-1545 is considered a high severity vulnerability due to its potential to allow remote attackers to escalate privileges and disclose sensitive information.
How do I fix CVE-2024-1545?
To fix CVE-2024-1545, upgrade WolfSSL to version 5.7.0 or later.
Who is affected by CVE-2024-1545?
CVE-2024-1545 affects systems running WolfSSL version 5.6.6 on both Linux and Windows operating systems.
What types of attacks can CVE-2024-1545 facilitate?
CVE-2024-1545 can facilitate information disclosure and privilege escalation attacks by co-resident attackers on the same system.
When was CVE-2024-1545 reported?
CVE-2024-1545 was reported in 2024 as a vulnerability in the WolfSSL library.