Executive brief
MatrixSSL, a lightweight TLS/SSL library often used in embedded and IoT devices, contains a flaw in its cryptographic calculations. This vulnerability could allow a remote attacker to potentially recover secret encryption keys by exploiting mathematical errors during secure connections. If successful, an attacker could decrypt sensitive communications or impersonate trusted services.
Technical details
A vulnerability exists in the pstm_exptmod function within MatrixSSL's bignum implementation. The function fails to properly perform modular exponentiation for certain inputs, leading to incorrect mathematical results. This issue is an incomplete fix for a previous vulnerability (CVE-2016-6887) where the vendor attempted to mitigate the issue by restricting modulus sizes rather than fixing the underlying calculation logic. A remote attacker can exploit these miscalculations to potentially recover or predict secret key material. The attack requires a high degree of complexity (AC:H) to successfully derive keys from the resulting mathematical errors.
Affected products
- MatrixSSL MatrixSSL 3.8.6 and earlier
Timeline
- 2016-08-01: disclosed: Vulnerability reported to vendor
- 2016-10-15: advisory: Public disclosure by The Fuzzing Project
- 2017-01-13: other: NVD publication date