5.9

CVE-2018-0735

The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).

Data is provided by the National Vulnerability Database (NVD)
OpenSSLOpenSSL Version >= 1.1.0 <= 1.1.0i
OpenSSLOpenSSL Version1.1.1
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version16.04 SwEditionlts
CanonicalUbuntu Linux Version18.04 SwEditionlts
CanonicalUbuntu Linux Version18.10
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
NodejsNode.Js SwEdition- Version >= 10.0.0 < 10.12.0
NodejsNode.Js SwEdition- Version >= 11.0.0 < 11.3.0
NodejsNode.Js Version10.13.0 SwEditionlts
NetappCn1610 Firmware Version-
   NetappCn1610 Version-
NetappCloud Backup Version-
NetappElement Software Version-
NetappOncommand Unified Manager SwPlatformvsphere Version >= 9.4
NetappSmi-s Provider Version-
NetappSnapdrive Version- SwPlatformunix
NetappSnapdrive Version- SwPlatformwindows
NetappSteelstore Version-
OracleApi Gateway Version11.1.2.4.0
OracleApplication Server Version0.9.8
OracleApplication Server Version1.0.0
OracleApplication Server Version1.0.1
OracleMysql Version <= 5.6.42
OracleMysql Version >= 5.7.0 <= 5.7.24
OracleMysql Version >= 8.0.0 <= 8.0.13
OracleSecure Global Desktop Version5.4
OracleTuxedo Version12.1.1.0.0
OracleVm Virtualbox Version < 6.0.0
OracleVm Virtualbox Version >= 5.0.0 < 5.2.24
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 9.26% 0.925
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-327 Use of a Broken or Risky Cryptographic Algorithm

The product uses a broken or risky cryptographic algorithm or protocol.