CVE-2016-7438
MEDIUMWolfssl < 3.9.8 - Cryptographic Issue
Title source: ruleDescription
The C software implementation of ECC in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.
Scores
CVSS v3
5.5
EPSS
0.0013
EPSS Percentile
32.1%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-310
Status
published
Affected Products (2)
wolfssl/wolfssl
< 3.9.8
n/a/n/a
Timeline
Published
Dec 13, 2016
Tracked Since
Feb 18, 2026