CVE detail
CVE-2019-13629 — CVE-2019-13629
Published 2019-10-03 · Modified 2026-06-17 · Vendor matrixssl · Product matrixssl · Source nvd
MEDIUM
severity
CVSS-derived band
0.0124
EPSS probability
exploitation probability, 30d
66.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or a remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because crypto/pubkey/ecc_math.c scalar multiplication leaks the bit length of the scalar.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References