Record summary

CVE-2017-13099 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.

Description

wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is referred to as "ROBOT."

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List<3.12.2affected

Proofs of concept

1

Catalogued exploits

MetasploitScanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5Metasploit auxiliary PoCby Adam Cammack <adam_cammack[AT]rapid7.com> +4 moreNot analyzed1 file

Ruby · linked to 10 vulnerabilities

Metasploit

PoC details

References

7