Junglewise Threat Intelligence

CVE-2016-8671: MatrixSSL cryptographic key recovery via pstm_exptmod miscalculation

CVE-2016-8671 · Severity: medium · CVSS 5.9 · Published 2017-01-13

Technologies: Matrixssl. Vendors: Matrixssl.

Executive brief

MatrixSSL, a lightweight TLS/SSL library often used in embedded and IoT devices, contains a flaw in its cryptographic calculations. This vulnerability could allow a remote attacker to potentially recover secret encryption keys by exploiting mathematical errors during secure connections. If successful, an attacker could decrypt sensitive communications or impersonate trusted services.

Technical details

A vulnerability exists in the pstm_exptmod function within MatrixSSL's bignum implementation. The function fails to properly perform modular exponentiation for certain inputs, leading to incorrect mathematical results. This issue is an incomplete fix for a previous vulnerability (CVE-2016-6887) where the vendor attempted to mitigate the issue by restricting modulus sizes rather than fixing the underlying calculation logic. A remote attacker can exploit these miscalculations to potentially recover or predict secret key material. The attack requires a high degree of complexity (AC:H) to successfully derive keys from the resulting mathematical errors.

Affected products

  • MatrixSSL MatrixSSL 3.8.6 and earlier

Timeline

  • 2016-08-01: disclosed: Vulnerability reported to vendor
  • 2016-10-15: advisory: Public disclosure by The Fuzzing Project
  • 2017-01-13: other: NVD publication date

References

Related threats