CVE-2017-1712

Severity CVSS v4.0:
Pending analysis
Type:
CWE-326 Inadequate Encryption Strength
Publication date:
01/07/2020
Last modified:
10/07/2020

Description

"A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a vulnerable TLS stack implementation to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hcltech:domino:*:*:*:*:*:*:*:* 9.0.1 (excluding)