CVE-2017-17428

Severity CVSS v4.0:
Pending analysis
Type:
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Publication date:
05/03/2018
Last modified:
03/10/2019

Description

Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cavium:nitrox_ssl_sdk:*:*:*:*:*:*:*:* 6.1.0 (including)
cpe:2.3:a:cavium:nitrox_v_ssl_sdk:*:*:*:*:*:*:*:* 1.2 (including)
cpe:2.3:a:cavium:octeon_sdk:*:*:*:*:*:*:*:* 1.7.2 (including)
cpe:2.3:a:cavium:octeon_ssl_sdk:*:*:*:*:*:*:*:* 1.5.0 (including)
cpe:2.3:a:cavium:turbossl_sdk:*:*:*:*:*:*:*:* 1.0 (including)
cpe:2.3:a:cisco:webex_conect_im:7.24.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:webex_meetings:t31:*:*:*:*:*:*:*
cpe:2.3:a:cisco:webex_meetings:t32:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ace4710_application_control_engine_firmware:3.0\(0\)a5\(2.0\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ace4710_application_control_engine_firmware:3.0\(0\)a5\(3.0\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ace4710_application_control_engine_firmware:3.0\(0\)a5\(3.5\):*:*:*:*:*:*:*
cpe:2.3:h:cisco:ace_4710_application_control_engine:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ace30_application_control_engine_module_firmware:3.0\(0\)a5\(2.0\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ace30_application_control_engine_module_firmware:3.0\(0\)a5\(3.0\):*:*:*:*:*:*:*
cpe:2.3:o:cisco:ace30_application_control_engine_module_firmware:3.0\(0\)a5\(3.5\):*:*:*:*:*:*:*