First published: Wed May 16 2018(Updated: )
Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote attacker, who has captured a pre-recorded SSL session inspected by SSLV, can establish large numbers of crafted SSL connections to the target and obtain the session keys required to decrypt the pre-recorded SSL session.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Symantec Intelligencecenter | =3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18268 is considered a high severity vulnerability due to its potential to allow attackers to decrypt SSL session keys.
To mitigate CVE-2017-18268, ensure that you update Symantec IntelligenceCenter to a patched version that addresses the vulnerability.
CVE-2017-18268 affects users of Symantec IntelligenceCenter version 3.3.
Yes, CVE-2017-18268 can be exploited remotely by attackers who have captured SSL sessions.
The primary attack method associated with CVE-2017-18268 is the Return of the Bleichenbacher Oracle Threat (ROBOT) attack.