Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-1545


Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges via Rowhammer fault injection to the RsaKey structure.


Published

2024-08-29T23:15:10.263

Last Modified

2024-09-04T14:27:08.060

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-252
    CWE-1256
  • Type: Primary
    CWE-74

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application wolfssl wolfssl 5.6.6 Yes
Operating System linux linux_kernel - No
Operating System microsoft windows - No

References