Lucene search

K
cve[email protected]CVE-2013-1623
HistoryFeb 08, 2013 - 7:55 p.m.

CVE-2013-1623

2013-02-0819:55:01
CWE-310
web.nvd.nist.gov
43
cve-2013-1623
wolfssl
cyassl
timing side-channel attacks
remote attackers
tls
dtls
plaintext-recovery attacks

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.4 Medium

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.3%

The TLS and DTLS implementations in wolfSSL CyaSSL before 2.5.0 do not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

Affected configurations

NVD
Node
yasslcyasslRange2.4.6
OR
yasslcyasslMatch0.2.0
OR
yasslcyasslMatch0.3.0
OR
yasslcyasslMatch0.4.0
OR
yasslcyasslMatch0.5.0
OR
yasslcyasslMatch0.5.5
OR
yasslcyasslMatch0.6.0
OR
yasslcyasslMatch0.6.2
OR
yasslcyasslMatch0.6.3
OR
yasslcyasslMatch0.8.0
OR
yasslcyasslMatch0.9.0
OR
yasslcyasslMatch0.9.6
OR
yasslcyasslMatch0.9.8
OR
yasslcyasslMatch0.9.9
OR
yasslcyasslMatch1.0.0rc1
OR
yasslcyasslMatch1.0.0rc2
OR
yasslcyasslMatch1.0.0rc3
OR
yasslcyasslMatch1.0.2
OR
yasslcyasslMatch1.0.3
OR
yasslcyasslMatch1.0.6
OR
yasslcyasslMatch1.1.0
OR
yasslcyasslMatch1.2.0
OR
yasslcyasslMatch1.3.0
OR
yasslcyasslMatch1.4.0
OR
yasslcyasslMatch1.5.0
OR
yasslcyasslMatch1.5.4
OR
yasslcyasslMatch1.5.6
OR
yasslcyasslMatch1.6.0
OR
yasslcyasslMatch1.6.5
OR
yasslcyasslMatch1.8.0
OR
yasslcyasslMatch1.9.0
OR
yasslcyasslMatch2.0.0rc1
OR
yasslcyasslMatch2.0.0rc2
OR
yasslcyasslMatch2.0.0rc3
OR
yasslcyasslMatch2.0.2
OR
yasslcyasslMatch2.0.6
OR
yasslcyasslMatch2.0.8
OR
yasslcyasslMatch2.2.0
OR
yasslcyasslMatch2.3.0
OR
yasslcyasslMatch2.4.0

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.4 Medium

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.3%