CVE-2017-5670: Infoleak
Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate attackers to obtain sensitive information by reading raw disk blocks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5670?
CVE-2017-5670 is rated as a high-severity vulnerability due to its potential for sensitive information disclosure.
How do I fix CVE-2017-5670?
To mitigate CVE-2017-5670, upgrade Riverbed RiOS to a version later than 9.6.0 where this vulnerability is addressed.
What types of attacks does CVE-2017-5670 enable?
CVE-2017-5670 allows physically proximate attackers to access sensitive information by reading raw disk blocks after the secure vault is deleted.
On which versions of Riverbed RiOS does CVE-2017-5670 affect?
CVE-2017-5670 affects Riverbed RiOS versions up to and including 9.6.0.
What is the main vulnerability in CVE-2017-5670?
The main vulnerability in CVE-2017-5670 involves the improper deletion of the secure vault using the rm program instead of more secure deletion methods.