CVE-2020-15309
published 2020-08-21CVE-2020-15309: An issue was discovered in wolfSSL before 4.5.0, when single precision is not employed. Local attackers can conduct a cache-timing attack against public key…
PriorityP427high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.34%
26.5th percentile
An issue was discovered in wolfSSL before 4.5.0, when single precision is not employed. Local attackers can conduct a cache-timing attack against public key operations. These attackers may already have obtained sensitive information if the affected system has been used for private key operations (e.g., signing with a private key).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wolfssl | < wolfssl 4.5.0+dfsg-1 (bookworm) | wolfssl 4.5.0+dfsg-1 (bookworm) |
| wolfssl | wolfssl | < 4.5.0 | 4.5.0 |
| wolfssl | wolfssl | >= 0 < 4.5.0+dfsg-1 | 4.5.0+dfsg-1 |
| wolfssl | wolfssl | >= 0 < 4.5.0+dfsg-1 | 4.5.0+dfsg-1 |
| wolfssl | wolfssl | >= 0 < 4.5.0+dfsg-1 | 4.5.0+dfsg-1 |
| wolfssl | wolfssl | >= 0 < 4.5.0+dfsg-1 | 4.5.0+dfsg-1 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.0HIGH
vendor_debian7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hrmr-g9x6-f5v8: An issue was discovered in wolfSSL before 4
ghsa_unreviewed·2022-05-24
CVE-2020-15309 [MEDIUM] CWE-362 GHSA-hrmr-g9x6-f5v8: An issue was discovered in wolfSSL before 4
An issue was discovered in wolfSSL before 4.5.0, when single precision is not employed. Local attackers can conduct a cache-timing attack against public key operations. These attackers may already have obtained sensitive information if the affected system has been used for private key operations (e.g., signing with a private key).
OSV
CVE-2020-15309: An issue was discovered in wolfSSL before 4
osv·2020-08-21·CVSS 7.0
CVE-2020-15309 [HIGH] CVE-2020-15309: An issue was discovered in wolfSSL before 4
An issue was discovered in wolfSSL before 4.5.0, when single precision is not employed. Local attackers can conduct a cache-timing attack against public key operations. These attackers may already have obtained sensitive information if the affected system has been used for private key operations (e.g., signing with a private key).
Debian
CVE-2020-15309: wolfssl - An issue was discovered in wolfSSL before 4.5.0, when single precision is not em...
vendor_debian·2020·CVSS 7.0
CVE-2020-15309 [HIGH] CVE-2020-15309: wolfssl - An issue was discovered in wolfSSL before 4.5.0, when single precision is not em...
An issue was discovered in wolfSSL before 4.5.0, when single precision is not employed. Local attackers can conduct a cache-timing attack against public key operations. These attackers may already have obtained sensitive information if the affected system has been used for private key operations (e.g., signing with a private key).
Scope: local
bookworm: resolved (fixed in 4.5.0+dfsg-1)
bullseye: resolved (fixed in 4.5.0+dfsg-1)
forky: resolved (fixed in 4.5.0+dfsg-1)
sid: resolved (fixed in 4.5.0+dfsg-1)
trixie: resolved (fixed in 4.5.0+dfsg-1)
No detection rules found.
No public exploits indexed.
2020-08-21
Published