CVE-2013-5915: Polarssl

Medium severity, CVSS 4.3. EPSS: 2.1% chance of exploitation in the next 30 days.

The RSA-CRT implementation in PolarSSL before 1.2.9 does not properly perform Montgomery multiplication, which might allow remote attackers to conduct a timing side-channel attack and retrieve RSA private keys.

Affected products

  • Polarssl Polarssl: up to and including 1.2.8; version 0.10.0 only; version 0.10.1 only; version 0.11.0 only; version 0.11.1 only; version 0.12.0 only; …

Published 2013-10-04. Last modified 2026-06-16.