PT-2021-6812 · Wolfssl+1 · Wolfssl+1

Published

2021-02-03

·

Updated

2021-07-22

·

CVE-2021-24116

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions wolfSSL versions prior to 4.6.0
Description The issue is related to a side-channel vulnerability in base64 PEM file decoding, which allows attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack. This can be particularly problematic in isolated environments that can be single stepped, such as Intel SGX. The vulnerability is also associated with the use of base64 decoding functionality with non-constant execution time, potentially allowing a remote attacker to access confidential data.
Recommendations For wolfSSL versions prior to 4.6.0, update to version 4.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the base64 decoding functionality to minimize the risk of exploitation.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1202
BDU:2022-02235
CVE-2021-24116

Affected Products

Alt Linux
Wolfssl