cisco-sa-20171212-bleichenbacher: Bleichenbacher Attack on TLS Affecting Cisco Products: December 2017
Published Dec 12, 2017
·Updated
Credit
Hanno Böck(Ruhr), Juraj Somorovsky(Ruhr), Craig Young(Tripwire VERT), (testssl), Dirk Wetter(testssl)
Affected Software
1 affected component
cisco Cisco Products
Remediation
Event History
Dec 12, 2017
Advisory Published
03:45 PM
Data Sourced
03:45 PM
RemedyDescriptionSeverityWeaknessAffected Software
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of cisco-sa-20171212-bleichenbacher?
The severity of cisco-sa-20171212-bleichenbacher is medium with a score of 5.3.
2
What is the impact of cisco-sa-20171212-bleichenbacher?
The impact of cisco-sa-20171212-bleichenbacher is primarily an information leak due to vulnerabilities in the TLS implementation.
3
How do I fix cisco-sa-20171212-bleichenbacher?
To fix cisco-sa-20171212-bleichenbacher, disable the use of TLS ciphers that rely on RSA for key exchange.
4
Which Cisco products are affected by cisco-sa-20171212-bleichenbacher?
Cisco products that implement vulnerable TLS configurations are affected by cisco-sa-20171212-bleichenbacher.
5
What is the nature of the vulnerability in cisco-sa-20171212-bleichenbacher?
The vulnerability in cisco-sa-20171212-bleichenbacher is an exploit related to the Bleichenbacher attack on TLS.