CVE-2017-17428
Summary
| CVE | CVE-2017-17428 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-05 18:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack. |
Risk And Classification
Problem Types: CWE-327
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Application Control Engine TLS Side Channel Leakage Flaw Lets Remote Users Decrypt TLS Session Data - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Security Advisory | CONFIRM | www.cavium.com | Vendor Advisory |
| VU#144389 - TLS implementations may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding | CERT-VN | www.kb.cert.org | Third Party Advisory, US Government Resource |
| Bleichenbacher Attack on TLS Affecting Cisco Products: December 2017 | CISCO | tools.cisco.com | Third Party Advisory |
| Multiple Cisco Products Multiple Information Disclosure Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.