Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-6935
HistoryFeb 09, 2024 - 12:00 a.m.

CVE-2023-6935

2024-02-0900:00:00
ubuntu.com
ubuntu.com
14
wolfssl
rsa
vulnerability
marvin attack
bleichenbacher
timing attack
cipher suite.

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

0.0004 Low

EPSS

Percentile

9.2%

wolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack,
new variation of a timing Bleichenbacher style attack, when built with the
following options to configure: --enable-all CFLAGS=“-DWOLFSSL_STATIC_RSA”
The define “WOLFSSL_STATIC_RSA” enables static RSA cipher suites, which is
not recommended, and has been disabled by default since wolfSSL 3.6.6.
Therefore the default build since 3.6.6, even with “–enable-all”, is not
vulnerable to the Marvin Attack. The vulnerability is specific to static
RSA cipher suites, and expected to be padding-independent. The
vulnerability allows an attacker to decrypt ciphertexts and forge
signatures after probing with a large number of test observations. However
the server’s private key is not exposed.

Bugs

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

0.0004 Low

EPSS

Percentile

9.2%