CVE-2017-17428: High severity Cavium Nitrox Ssl Sdk vulnerability
Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-17428?
CVE-2017-17428 refers to a vulnerability in Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) that allows remote attackers to decrypt TLS ciphertext data.
How severe is CVE-2017-17428?
CVE-2017-17428 has a severity value of 5.9, which is considered high.
What software is affected by CVE-2017-17428?
The following software versions are affected: Cavium Nitrox SSL SDK up to version 6.1.0, Cavium Nitrox V SSL SDK up to version 1.2, Cavium Octeon SDK up to version 1.7.2, Cavium Octeon SSL SDK up to version 1.5.0, and Cavium TurboSSL SDK up to version 1.0.
How can the vulnerability in CVE-2017-17428 be exploited?
The vulnerability in CVE-2017-17428 can be exploited by leveraging a Bleichenbacher RSA padding oracle, also known as a ROBOT attack.
Where can I find more information about CVE-2017-17428?
You can find more information about CVE-2017-17428 at the following references: [1] http://www.securityfocus.com/bid/102170, [2] http://www.securitytracker.com/id/1039984, [3] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171212-bleichenbacher