VDB
CVE-2013-1623
CVE-2013-1623
PUBLISHED
CVSS 4.300000190734863 MEDIUM
The TLS and DTLS implementations in wolfSSL CyaSSL before 2.5.0 do not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
EPSS 0.93% · 76.5th percentile
Risk Scores
CVSS v2.0
4.300000190734863
EPSS Score
0.93%
76.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| yassl | cyassl | 0.2.0, 0.3.0, 0.4.0 |
Timeline
- Feb 8, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 17, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 1, 2023 EPSS Score
- May 24, 2023 EPSS Score
- Jul 15, 2023 EPSS Score
References
- http://www.isg.rhul.ac.uk/tls/TLStiming.pdf url
- [oss-security] 20130205 Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations mailing-list
- 53372 third-party-advisory
- GLSA-201308-06 vendor-advisory
- http://www.yassl.com/yaSSL/Blog/Entries/2013/2/5_WolfSSL%2C_provider_of_CyaSSL_Embedded_SSL%2C_releases_first_embedded_TLS_and_DTLS_protocol_fix_for_Lucky_Thirteen_Attack.html url
- https://nvd.nist.gov/vuln/detail/CVE-2013-1623 advisory