Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3343
HistoryJan 26, 2017 - 8:01 a.m.

Side Channel Attack On Modular Exponentiation

2017-01-2608:01:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.002 Low

EPSS

Percentile

51.7%

OpenSSL is vulnerable to side channel attacks. The vulnerability exploits cache-bank conflicts on the Intel Sandy-Bridge microarchitecture, exposing RSA keys. However, an attacker can only exploit this only if he has control of code in a thread running on the same hyper-threaded core as the victim thread who is executing decryption process.

References