CVE-2017-13099
published 2017-12-13CVE-2017-13099: wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover…
PriorityP341medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
24.92%
97.7th percentile
wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is referred to as "ROBOT."
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arubanetworks | instant | < 6.5.4.6 | 6.5.4.6 |
| debian | wolfssl | < wolfssl 3.13.0+dfsg-1 (bookworm) | wolfssl 3.13.0+dfsg-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.4.0-145.171 | 4.4.0-145.171 |
| siemens | scalance_w1750d_firmware | < 8.3.0.1 | 8.3.0.1 |
| wolfssl | wolfssl | < 3.12.2 | 3.12.2 |
| wolfssl | wolfssl | — | — |
| wolfssl | wolfssl | >= 0 < 3.13.0+dfsg-1 | 3.13.0+dfsg-1 |
| wolfssl | wolfssl | >= 0 < 3.13.0+dfsg-1 | 3.13.0+dfsg-1 |
| wolfssl | wolfssl | >= 0 < 3.13.0+dfsg-1 | 3.13.0+dfsg-1 |
| wolfssl | wolfssl | >= 0 < 3.13.0+dfsg-1 | 3.13.0+dfsg-1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Target any TLS session using RSA key exchange cipher suites against wolfSSL prior to 3.12.2; the library returns a weak Bleichenbacher oracle response distinguishable from a valid pre-master secret, enabling private key recovery. ↗
- →Monitor for repeated TLS RSA ClientKeyExchange messages with subtly malformed PKCS#1 v1.5 padding sent to the same server — a hallmark of Bleichenbacher (ROBOT) oracle probing. ↗
- →On Siemens SCALANCE W1750D, detect exploitation attempts by monitoring for high-volume TLS handshake anomalies (repeated RSA key-exchange attempts) from a single source IP against the device's web interface. ↗
- ·Vulnerability only exists when RSA key exchange cipher suites are enabled; disabling all RSA key exchange cipher suites (e.g., enforcing ECDHE/DHE) eliminates the oracle surface entirely. ↗
- ·Siemens SCALANCE W1750D is only affected on versions prior to v8.3.0.1; confirm firmware version before triaging alerts. ↗
- ·Exploitation requires the attacker to both probe the oracle AND observe legitimate TLS traffic; passive-only or active-only network positions are insufficient for full key recovery. ↗
- ·CVSS v3 Attack Complexity is rated High (AC:H), reflecting the multi-step nature of the Bleichenbacher oracle attack; do not treat this as trivially exploitable in automated scanning contexts. ↗
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.0HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-97gp-82pc-qc6x: wolfSSL prior to version 3
ghsa_unreviewed·2022-05-13
CVE-2017-13099 [MEDIUM] CWE-203 GHSA-97gp-82pc-qc6x: wolfSSL prior to version 3
wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is referred to as "ROBOT."
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2019-04-02·CVSS 7.0
CVE-2017-18249 linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that a race condition existed in the f2fs file system
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service. (CVE-2017-18249)
Wen Xu discovered that the f2fs file system implementation in the Linux
kernel did not properly validate metadata. An attacker could use this to
construct a malicious f2fs image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13097, CVE-2018-13099, CVE-2018-13100,
CVE-2018-14614, CVE-2018-14616)
Wen Xu and Po-Ning Tseng discovered that btrfs file system implementation
in the Linux kernel did not properly validate metadata. An attacker could
use this to construct a malicious btrfs image that, when mo
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2019-04-02·CVSS 7.0
CVE-2017-18249 linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3932-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that a race condition existed in the f2fs file system
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service. (CVE-2017-18249)
Wen Xu discovered that the f2fs file system implementation in the Linux
kernel did not properly validate metadata. An attacker could use this to
construct a malicious f2fs image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13097, CVE-2018-13099, CVE-2018-13100,
CVE-2018-14614, CVE-2018-14616)
Wen Xu and Po-Ning Tseng
OSV
CVE-2017-13099: wolfSSL prior to version 3
osv·2017-12-13·CVSS 5.9
CVE-2017-13099 [MEDIUM] CVE-2017-13099: wolfSSL prior to version 3
wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is referred to as "ROBOT."
CISA ICS
Siemens SCALANCE W1750D
cisa_ics·2018-10-09·CVSS 7.5
[HIGH] Siemens SCALANCE W1750D
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE W1750D
Last RevisedOctober 09, 2018
Alert CodeICSA-18-282-02
## 1. EXECUTIVE SUMMARY
-
CVSS v3 5.9
- ATTENTION: Exploitable remotely/public exploits are available
- Vendor: Siemens
- Equipment: SCALANCE W1750D
- Vulnerability: Cryptographic issues
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to decrypt TLS traffic.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports the vulnerability affects the following SCALANCE W1750D products:
- SCALANCE W1750D: All versions prior to v8.3.0.1
## 3.2 VULNE
Debian
CVE-2017-13099: wolfssl - wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any T...
vendor_debian·2017·CVSS 7.5
CVE-2017-13099 [HIGH] CVE-2017-13099: wolfssl - wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any T...
wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is referred to as "ROBOT."
Scope: local
bookworm: resolved (fixed in 3.13.0+dfsg-1)
bullseye: resolved (fixed in 3.13.0+dfsg-1)
forky: resolved (fixed in 3.13.0+dfsg-1)
sid: resolved (fixed in 3.13.0+dfsg-1)
trixie: resolved (fixed in 3.13.0+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-002.txthttp://www.kb.cert.org/vuls/id/144389http://www.securityfocus.com/bid/102174https://cert-portal.siemens.com/productcert/pdf/ssa-464260.pdfhttps://github.com/wolfSSL/wolfssl/pull/1229https://robotattack.org/http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-002.txthttp://www.kb.cert.org/vuls/id/144389http://www.securityfocus.com/bid/102174https://cert-portal.siemens.com/productcert/pdf/ssa-464260.pdfhttps://github.com/wolfSSL/wolfssl/pull/1229https://robotattack.org/
2017-12-13
Published