CVE-2023-6935 describes a timing-based Bleichenbacher-style attack, known as the Marvin Attack, affecting the wolfSSL SP Math All RSA implementation when specifically configured with "--enable-all CFLAGS="-DWOLFSSL_STATIC_RSA"". This vulnerability, present in static RSA cipher suites, allows an attacker to decrypt ciphertexts and forge signatures after extensive probing, though it does not expose the server's private key. Rated as Medium severity (CVSS 5.9), the attack requires high attack complexity and network access, impacting confidentiality. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.12.2, <= 5.6.4CPE match | cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.