CVE-2017-13099 describes a weak Bleichenbacher oracle vulnerability in wolfSSL versions prior to 3.12.2, affecting products from vendors like Aruba Networks and Siemens. This flaw, known as "ROBOT," allows an unauthenticated attacker to recover the private key from a vulnerable application when an RSA key exchange TLS cipher suite is used. Rated as Medium severity (CVSS 5.9), it has a high impact on confidentiality with high attack complexity. While not listed in CISA KEV, a Metasploit module exists for scanning, and it has garnered significant community discussion and media coverage, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.12.2CPE matchmatch criteria | cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* | ||
< 8.3.0.1CPE matchmatch criteria | cpe:2.3:o:siemens:scalance_w1750d_firmware:*:*:*:*:*:*:*:* | ||
< 6.5.4.6CPE matchmatch criteria | cpe:2.3:a:arubanetworks:instant:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.