← Back

CVE-2013-1623

nvd nist
Published: Feb 8, 2013Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The TLS and DTLS implementations in wolfSSL CyaSSL before 2.5.0 do not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

Affected (40)

Products: Yassl: Cyassl
1 product
Cyassl
Configuration A
40 vulnerable
Vulnerable SoftwareAffected Versions
Yassl
Up to 2.4.6
Version 0.2.0
Version 0.3.0
Version 0.4.0
Version 0.5.0
Version 0.5.5
Version 0.6.0
Version 0.6.2
Version 0.6.3
Version 0.8.0
Version 0.9.0
Version 0.9.6
Version 0.9.8
Version 0.9.9
Version 1.0.0 rc1
Version 1.0.0 rc2
Version 1.0.0 rc3
Version 1.0.2
Version 1.0.3
Version 1.0.6
Version 1.1.0
Version 1.2.0
Version 1.3.0
Version 1.4.0
Version 1.5.0
Version 1.5.4
Version 1.5.6
Version 1.6.0
Version 1.6.5
Version 1.8.0
Version 1.9.0
Version 2.0.0 rc1
Version 2.0.0 rc2
Version 2.0.0 rc3
Version 2.0.2
Version 2.0.6
Version 2.0.8
Version 2.2.0
Version 2.3.0
Version 2.4.0

Related CWEs

Timeline

No history available yet.