7.1
CVE-2017-17428
- EPSS 78.88%
- Veröffentlicht 05.03.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:17:55
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cavium ≫ Nitrox Ssl Sdk Version <= 6.1.0
Cavium ≫ Nitrox V Ssl Sdk Version <= 1.2
Cavium ≫ Octeon Sdk Version <= 1.7.2
Cavium ≫ Octeon Ssl Sdk Version <= 1.5.0
Cavium ≫ Turbossl Sdk Version <= 1.0
Cisco ≫ Webex Conect Im Version7.24.1
Cisco ≫ Webex Meetings Versiont31
Cisco ≫ Webex Meetings Versiont32
Cisco ≫ Ace4710 Application Control Engine Firmware Version3.0(0)a5(2.0)
Cisco ≫ Ace4710 Application Control Engine Firmware Version3.0(0)a5(3.0)
Cisco ≫ Ace4710 Application Control Engine Firmware Version3.0(0)a5(3.5)
Cisco ≫ Ace30 Application Control Engine Module Firmware Version3.0(0)a5(2.0)
Cisco ≫ Ace30 Application Control Engine Module Firmware Version3.0(0)a5(3.0)
Cisco ≫ Ace30 Application Control Engine Module Firmware Version3.0(0)a5(3.5)
Cisco ≫ Adaptive Security Appliance 5520 Firmware Version9.1(7.16)
Cisco ≫ Adaptive Security Appliance 5540 Firmware Version9.1(7.16)
Cisco ≫ Adaptive Security Appliance 5550 Firmware Version9.1(7.16)
Cisco ≫ Adaptive Security Appliance 5510 Firmware Version9.1(7.16)
Cisco ≫ Adaptive Security Appliance 5505 Firmware Version9.1(7.16)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 78.88% | 0.99 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 7.1 | 8.6 | 6.9 |
AV:N/AC:M/Au:N/C:C/I:N/A:N
|
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.