7.5
CVE-2015-5738
- EPSS 0.51%
- Published 26.07.2016 17:59:00
- Last modified 12.04.2025 10:46:40
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS), makes it easier for remote attackers to obtain private RSA keys by conducting a Lenstra side-channel attack.
Data is provided by the National Vulnerability Database (NVD)
Marvell ≫ Software Development Kit Version2.0
Marvell ≫ Octeon Ii Cn6000 Version-
Marvell ≫ Octeon Ii Cn6010 Version-
Marvell ≫ Octeon Ii Cn6020 Version-
Marvell ≫ Octeon Ii Cn6010 Version-
Marvell ≫ Octeon Ii Cn6020 Version-
F5 ≫ Traffix Signaling Delivery Controller Version >= 3.3.2 <= 3.5.1
F5 ≫ Traffix Signaling Delivery Controller Version >= 4.0.0 <= 4.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.51% | 0.634 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.