First published: Mon Mar 05 2018(Updated: )
Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cavium Nitrox Ssl Sdk | <=6.1.0 | |
Cavium Nitrox V Ssl Sdk | <=1.2 | |
Cavium Octeon Sdk | <=1.7.2 | |
Cavium Octeon Ssl Sdk | <=1.5.0 | |
Cavium Turbossl Sdk | <=1.0 | |
Cisco Webex Conect Im | =7.24.1 | |
Cisco Webex Meetings | =t31 | |
Cisco Webex Meetings | =t32 | |
Cisco Ace4710 Application Control Engine Firmware | =3.0\(0\)a5\(2.0\) | |
Cisco Ace4710 Application Control Engine Firmware | =3.0\(0\)a5\(3.0\) | |
Cisco Ace4710 Application Control Engine Firmware | =3.0\(0\)a5\(3.5\) | |
Cisco Ace 4710 Application Control Engine | ||
Cisco Ace30 Application Control Engine Module Firmware | =3.0\(0\)a5\(2.0\) | |
Cisco Ace30 Application Control Engine Module Firmware | =3.0\(0\)a5\(3.0\) | |
Cisco Ace30 Application Control Engine Module Firmware | =3.0\(0\)a5\(3.5\) | |
Cisco Ace30 Application Control Engine Module | ||
Cisco Adaptive Security Appliance 5520 Firmware | =9.1\(7.16\) | |
Cisco Adaptive Security Appliance 5520 | ||
Cisco Adaptive Security Appliance 5540 Firmware | =9.1\(7.16\) | |
Cisco Adaptive Security Appliance 5540 | ||
Cisco Adaptive Security Appliance 5550 Firmware | =9.1\(7.16\) | |
Cisco Adaptive Security Appliance 5550 | ||
Cisco Adaptive Security Appliance 5510 Firmware | =9.1\(7.16\) | |
Cisco Adaptive Security Appliance 5510 | ||
Cisco Adaptive Security Appliance 5505 Firmware | =9.1\(7.16\) | |
Cisco Adaptive Security Appliance 5505 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17428 refers to a vulnerability in Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) that allows remote attackers to decrypt TLS ciphertext data.
CVE-2017-17428 has a severity value of 5.9, which is considered high.
The following software versions are affected: Cavium Nitrox SSL SDK up to version 6.1.0, Cavium Nitrox V SSL SDK up to version 1.2, Cavium Octeon SDK up to version 1.7.2, Cavium Octeon SSL SDK up to version 1.5.0, and Cavium TurboSSL SDK up to version 1.0.
The vulnerability in CVE-2017-17428 can be exploited by leveraging a Bleichenbacher RSA padding oracle, also known as a ROBOT attack.
You can find more information about CVE-2017-17428 at the following references: [1] http://www.securityfocus.com/bid/102170, [2] http://www.securitytracker.com/id/1039984, [3] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171212-bleichenbacher