Vulnerability Description
Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cavium | Nitrox Ssl Sdk | <= 6.1.0 |
| Cavium | Nitrox V Ssl Sdk | <= 1.2 |
| Cavium | Octeon Sdk | <= 1.7.2 |
| Cavium | Octeon Ssl Sdk | <= 1.5.0 |
| Cavium | Turbossl Sdk | <= 1.0 |
| Cisco | Webex Conect Im | 7.24.1 |
| Cisco | Webex Meetings | t31 |
| Cisco | Ace4710 Application Control Engine Firmware | 3.0\(0\)a5\(2.0\) |
| Cisco | Ace 4710 Application Control Engine | - |
| Cisco | Ace30 Application Control Engine Module Firmware | 3.0\(0\)a5\(2.0\) |
| Cisco | Ace30 Application Control Engine Module | - |
| Cisco | Adaptive Security Appliance 5520 Firmware | 9.1\(7.16\) |
| Cisco | Adaptive Security Appliance 5520 | - |
| Cisco | Adaptive Security Appliance 5540 Firmware | 9.1\(7.16\) |
| Cisco | Adaptive Security Appliance 5540 | - |
| Cisco | Adaptive Security Appliance 5550 Firmware | 9.1\(7.16\) |
| Cisco | Adaptive Security Appliance 5550 | - |
| Cisco | Adaptive Security Appliance 5510 Firmware | 9.1\(7.16\) |
| Cisco | Adaptive Security Appliance 5510 | - |
| Cisco | Adaptive Security Appliance 5505 Firmware | 9.1\(7.16\) |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/102170Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039984Third Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Third Party Advisory
- https://www.cavium.com/security-advisory-cve-2017-17428.htmlVendor Advisory
- https://www.kb.cert.org/vuls/id/144389Third Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/102170Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039984Third Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Third Party Advisory
- https://www.cavium.com/security-advisory-cve-2017-17428.htmlVendor Advisory
- https://www.kb.cert.org/vuls/id/144389Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2017-17428?
CVE-2017-17428 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT atta...
How severe is CVE-2017-17428?
CVE-2017-17428 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17428?
Check the references section above for vendor advisories and patch information. Affected products include: Cavium Nitrox Ssl Sdk, Cavium Nitrox V Ssl Sdk, Cavium Octeon Sdk, Cavium Octeon Ssl Sdk, Cavium Turbossl Sdk.