Impact
wolfSSH allows unauthenticated clients to send Diffie‑Hellman group‑exchange messages 31 and 33. The server incorrectly accepts these messages while in the pre‑authentication state, which triggers two 8‑round Miller‑Rabin primality tests on a prime of up to 8192 bits. These tests consume significant CPU time, potentially exhausting server resources before authentication occurs. The server then assumes a client‑role and responds, which can cause key‑exchange confusion but does not weaken cryptographic security. The vulnerability stems from improper input validation (CWE‑400), leading to resource exhaustion (CWE‑372) and role confusion (CWE‑405). The result is a moderate‑severity denial‑of‑service that can disrupt service availability.
Affected Systems
wolfSSL Inc. wolfSSH versions up to and including 1.5.0 are affected. All builds that permit the server to process SSH_MSG_KEX_DH_GEX_GROUP (31) and SSH_MSG_KEX_DH_GEX_REPLY (33) from an unauthenticated peer are vulnerable. Versions from 1.2.0 through 1.4.22 admit the same message and enter the same client‑role path without the primality cost.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. Exploitation is straightforward: an attacker merely connects to the server, negotiates a diffie‑hellman‑group‑exchange‑sha256 session, and sends message 31. No authentication or privileged access is required, making the vulnerability readily exploitable. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is clear, and the impact is to potentially degrade service availability before any authentication succeeds.
OpenCVE Enrichment