← Vulnerability feed

Vulnerability record · CVE-2017-13099 · published 13 December 2017

CVE-2017-13099: Wolfssl observable discrepancy vulnerability

Wolfssl · Wolfssl

wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is referred to as "ROBOT."

5.9 CVSS 3.0 Medium EPSS 25% · top 2.2% CWE-203 · Observable discrepancy
5.9CVSS 3.0 base score, v2 4.3
25%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is referred to as "ROBOT."

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-002.txt Third Party Advisory
http://www.kb.cert.org/vuls/id/144389 Issue TrackingMitigationThird Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/102174 Issue TrackingMitigationThird Party AdvisoryVDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-464260.pdf Third Party Advisory
https://github.com/wolfSSL/wolfssl/pull/1229 Issue TrackingPatchThird Party Advisory
https://robotattack.org/ Issue TrackingThird Party Advisory
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-002.txt Third Party Advisory
http://www.kb.cert.org/vuls/id/144389 Issue TrackingMitigationThird Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/102174 Issue TrackingMitigationThird Party AdvisoryVDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-464260.pdf Third Party Advisory
https://github.com/wolfSSL/wolfssl/pull/1229 Issue TrackingPatchThird Party Advisory
https://robotattack.org/ Issue TrackingThird Party Advisory

Track CVE-2017-13099 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-5991Wolfssl out-of-bounds read vulnerabilityIn function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the fu…EPSS 0.56%9.8CVE-2022-37885Arubanetworks arubaos classic buffer overflow vulnerabilityThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending special…EPSS 1.5%9.8CVE-2022-37886Arubanetworks arubaos classic buffer overflow vulnerabilityThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending special…EPSS 1.5%9.8CVE-2022-37887Arubanetworks arubaos classic buffer overflow vulnerabilityThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending special…EPSS 1.7%9.8CVE-2022-37889Arubanetworks arubaos classic buffer overflow vulnerabilityThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending special…EPSS 1.7%9.8CVE-2022-37890Arubanetworks arubaos classic buffer overflow vulnerabilityUnauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web management interface. Successful exploitation res…EPSS 1.2%9.8CVE-2022-37891Arubanetworks arubaos classic buffer overflow vulnerabilityUnauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web management interface. Successful exploitation res…EPSS 1.2%9.8CVE-2022-37888Arubanetworks arubaos classic buffer overflow vulnerabilityThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending special…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2017-13099), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.