MEDIUM · 5.9

CVE-2017-17428

Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT atta...

Vulnerability Description

Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.

CVSS Score

5.9

MEDIUM

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
CaviumNitrox Ssl Sdk<= 6.1.0
CaviumNitrox V Ssl Sdk<= 1.2
CaviumOcteon Sdk<= 1.7.2
CaviumOcteon Ssl Sdk<= 1.5.0
CaviumTurbossl Sdk<= 1.0
CiscoWebex Conect Im7.24.1
CiscoWebex Meetingst31
CiscoAce4710 Application Control Engine Firmware3.0\(0\)a5\(2.0\)
CiscoAce 4710 Application Control Engine-
CiscoAce30 Application Control Engine Module Firmware3.0\(0\)a5\(2.0\)
CiscoAce30 Application Control Engine Module-
CiscoAdaptive Security Appliance 5520 Firmware9.1\(7.16\)
CiscoAdaptive Security Appliance 5520-
CiscoAdaptive Security Appliance 5540 Firmware9.1\(7.16\)
CiscoAdaptive Security Appliance 5540-
CiscoAdaptive Security Appliance 5550 Firmware9.1\(7.16\)
CiscoAdaptive Security Appliance 5550-
CiscoAdaptive Security Appliance 5510 Firmware9.1\(7.16\)
CiscoAdaptive Security Appliance 5510-
CiscoAdaptive Security Appliance 5505 Firmware9.1\(7.16\)

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-17428?

CVE-2017-17428 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT atta...

How severe is CVE-2017-17428?

CVE-2017-17428 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-17428?

Check the references section above for vendor advisories and patch information. Affected products include: Cavium Nitrox Ssl Sdk, Cavium Nitrox V Ssl Sdk, Cavium Octeon Sdk, Cavium Octeon Ssl Sdk, Cavium Turbossl Sdk.