CVE-2011-4574
CRITICALPolarSSL < 1.1.0 - Use of Cryptographically Weak PRNG via HAVEGE Algorithm
Title source: llmDescription
PolarSSL versions prior to v1.1 use the HAVEGE random number generation algorithm. At its heart, this uses timing information based on the processor's high resolution timer (the RDTSC instruction). This instruction can be virtualized, and some virtual machine hosts have chosen to disable this instruction, returning 0s or predictable results.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://tls.mbed.org/tech-updates/security-advisories/polarssl-security-advisory-2011-02
Scores
CVSS v3
9.8
EPSS
0.0105
EPSS Percentile
59.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-338
Status
published
Products (1)
polarssl/polarssl
< 1.1.0
Published
Oct 27, 2021
Tracked Since
Feb 18, 2026