CVE-2017-17428
Severity CVSS v4.0:
Pending analysis
Type:
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
Publication date:
05/03/2018
Last modified:
03/10/2019
Description
Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Base Score 2.0
7.10
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cavium:nitrox_ssl_sdk:*:*:*:*:*:*:*:* | 6.1.0 (including) | |
| cpe:2.3:a:cavium:nitrox_v_ssl_sdk:*:*:*:*:*:*:*:* | 1.2 (including) | |
| cpe:2.3:a:cavium:octeon_sdk:*:*:*:*:*:*:*:* | 1.7.2 (including) | |
| cpe:2.3:a:cavium:octeon_ssl_sdk:*:*:*:*:*:*:*:* | 1.5.0 (including) | |
| cpe:2.3:a:cavium:turbossl_sdk:*:*:*:*:*:*:*:* | 1.0 (including) | |
| cpe:2.3:a:cisco:webex_conect_im:7.24.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:webex_meetings:t31:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:webex_meetings:t32:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ace4710_application_control_engine_firmware:3.0\(0\)a5\(2.0\):*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ace4710_application_control_engine_firmware:3.0\(0\)a5\(3.0\):*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ace4710_application_control_engine_firmware:3.0\(0\)a5\(3.5\):*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:ace_4710_application_control_engine:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ace30_application_control_engine_module_firmware:3.0\(0\)a5\(2.0\):*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ace30_application_control_engine_module_firmware:3.0\(0\)a5\(3.0\):*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ace30_application_control_engine_module_firmware:3.0\(0\)a5\(3.5\):*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



