HIGH · 7.5

CVE-2015-5738

The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS), makes it easier for remo...

Vulnerability Description

The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS), makes it easier for remote attackers to obtain private RSA keys by conducting a Lenstra side-channel attack.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
MarvellSoftware Development Kit2.0
MarvellOcteon Ii Cn6000-
MarvellOcteon Ii Cn6010-
MarvellOcteon Ii Cn6020-
F5Traffix Signaling Delivery Controller>= 3.3.2, <= 3.5.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-5738?

CVE-2015-5738 is a vulnerability with a CVSS score of 7.5 (HIGH). The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS), makes it easier for remo...

How severe is CVE-2015-5738?

CVE-2015-5738 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-5738?

Check the references section above for vendor advisories and patch information. Affected products include: Marvell Software Development Kit, Marvell Octeon Ii Cn6000, Marvell Octeon Ii Cn6010, Marvell Octeon Ii Cn6020, F5 Traffix Signaling Delivery Controller.