CVE-2024-1543
Estado: AnalizadaMedia (5.5)—
The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacker with cache-line resolution. In a controlled environment such as Intel SGX, an attacker can gain a per instruction sub-cache-line resolution allowing them to break the cache-line-level protection. For details on the attack refer to: https://doi.org/10.46586/tches.v2024.i1.457-500
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-208
- CWE-203
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-1543",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-1543",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-08-30T14:19:28.685421Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "facts@wolfssl.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.1,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 0.5
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "facts@wolfssl.com",
"affectedData": [
{
"repo": "https://github.com/wolfSSL/wolfssl",
"vendor": "wolfSSL",
"product": "wolfSSL",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "Release",
"lessThanOrEqual": "5.6.5"
}
],
"programFiles": [
"wolfcrypt/src/aes.c"
],
"defaultStatus": "unknown"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:wolfssl:wolfcrypt:*:*:*:*:*:*:*:*"
],
"vendor": "wolfssl",
"product": "wolfcrypt",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "git",
"lessThanOrEqual": "5.6.6"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-08-29T23:15:10.067",
"references": [
{
"url": "https://github.com/wolfSSL/wolfssl/blob/master/ChangeLog.md#wolfssl-release-566-dec-19-2023",
"tags": [
"Release Notes"
],
"source": "facts@wolfssl.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "facts@wolfssl.com",
"description": [
{
"lang": "en",
"value": "CWE-208"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-203"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacker with cache-line resolution. In a controlled environment such as Intel SGX, an attacker can gain a per instruction sub-cache-line resolution allowing them to break the cache-line-level protection. For details on the attack refer to: https://doi.org/10.46586/tches.v2024.i1.457-500"
},
{
"lang": "es",
"value": "La implementación de T-Table protegida por canal lateral en wolfSSL hasta la versión 5.6.5 protege contra un atacante de canal lateral con resolución de línea de caché. En un entorno controlado como Intel SGX, un atacante puede obtener una resolución de línea de subcaché por instrucción que le permita romper la protección a nivel de línea de caché. Para obtener detalles sobre el ataque, consulte: https://doi.org/10.46586/tches.v2024.i1.457-500"
}
],
"lastModified": "2026-06-17T07:04:27.670",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57DCDF61-F982-41D7-83BE-DDAEC85A797A",
"versionEndExcluding": "5.6.6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "facts@wolfssl.com"
}