CVE-2018-5762
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/02/2018
Last modified:
03/10/2019
Description
The TLS implementation in the TCP/IP networking module in Unisys ClearPath MCP systems with TCP-IP-SW 58.1 before 58.160, 59.1 before 059.1a.17 (IC #17), and 60.0 before 60.044 might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:unisys:clearpath_mcp:*:*:*:*:*:*:*:* | 58.1 (including) | 58.160 (excluding) |
| cpe:2.3:a:unisys:clearpath_mcp:*:*:*:*:*:*:*:* | 59.1 (including) | 059.1a.17 (excluding) |
| cpe:2.3:a:unisys:clearpath_mcp:*:*:*:*:*:*:*:* | 60.0 (including) | 60.044 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



