5.9

CVE-2017-17841

Palo Alto Networks PAN-OS 6.1, 7.1, and 8.0.x before 8.0.7, when an interface implements SSL decryption with RSA enabled or hosts a GlobalProtect portal or gateway, might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PaloaltonetworksPan-os Version6.1.0
PaloaltonetworksPan-os Version7.1.0
PaloaltonetworksPan-os Version7.1.1
PaloaltonetworksPan-os Version7.1.2
PaloaltonetworksPan-os Version7.1.3
PaloaltonetworksPan-os Version7.1.4
PaloaltonetworksPan-os Version7.1.4-h2
PaloaltonetworksPan-os Version7.1.5
PaloaltonetworksPan-os Version7.1.6
PaloaltonetworksPan-os Version7.1.7
PaloaltonetworksPan-os Version7.1.8
PaloaltonetworksPan-os Version7.1.9
PaloaltonetworksPan-os Version7.1.10
PaloaltonetworksPan-os Version7.1.11
PaloaltonetworksPan-os Version7.1.12
PaloaltonetworksPan-os Version7.1.13
PaloaltonetworksPan-os Version7.1.14
PaloaltonetworksPan-os Version8.0.0
PaloaltonetworksPan-os Version8.0.1
PaloaltonetworksPan-os Version8.0.2
PaloaltonetworksPan-os Version8.0.3
PaloaltonetworksPan-os Version8.0.4
PaloaltonetworksPan-os Version8.0.5
PaloaltonetworksPan-os Version8.0.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.46% 0.803
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N