CVE-2017-13099: Arubanetworks Instant

Medium severity, CVSS 5.9. EPSS: 24.9% chance of exploitation in the next 30 days.

wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is referred to as "ROBOT."

Affected products

  • Arubanetworks Instant: before 6.5.4.6 (fixed in 6.5.4.6)
  • Siemens Scalance w1750d Firmware: before 8.3.0.1 (fixed in 8.3.0.1)
  • wolfSSL wolfSSL: before 3.12.2 (fixed in 3.12.2)

Published 2017-12-13. Last modified 2026-06-17.