wolfSSL
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*
- < 5.8.4
A vulnerability exists in wolfSSL versions prior to 5.8.4, where multiple constant-time implementations may be altered into non-constant-time binaries by LLVM optimizations. This alteration can create observable timing differences, potentially leading to information disclosure through timing side-channel attacks.
Exploitation of this vulnerability could allow for information disclosure via timing side-channel attacks, taking advantage of the introduced timing discrepancies.
Users can update to wolfSSL version 5.8.4 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.