CVE-2017-17428Use of a Broken or Risky Cryptographic Algorithm in Nitrox SSL SDK

Severity
5.9MEDIUMNVD
EPSS
77.0%
top 1.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 5
Latest updateMay 13

Description

Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages14 packages

🔴Vulnerability Details

2
GHSA
GHSA-gw93-27cv-rc7m: Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a B2022-05-13
CVEList
CVE-2017-17428: Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a B2018-03-05

📋Vendor Advisories

1
Cisco
Bleichenbacher Attack on TLS Affecting Cisco Products: December 20172017-12-12
CVE-2017-17428 — Cavium Nitrox SSL SDK vulnerability | cvebase