CVE-2017-17428
5.9
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD
Description
Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
Affected (19)
Products: Cavium: Nitrox Ssl Sdk, Nitrox V Ssl Sdk, Octeon Sdk, Octeon Ssl Sdk, Turbossl Sdk · Cisco: Webex Conect Im, Webex Meetings, Ace4710 Application Control Engine Firmware, Ace30 Application Control Engine Module Firmware, Adaptive Security Appliance 5520 Firmware, Adaptive Security Appliance 5540 Firmware, Adaptive Security Appliance 5550 Firmware, Adaptive Security Appliance 5510 Firmware, Adaptive Security Appliance 5505 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.1.0 | |
| Up to 1.2 | |
| Up to 1.7.2 | |
| Up to 1.5.0 | |
| Up to 1.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.24.1 | |
| Version t31 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0(0)a5(2.0) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ace 4710 Application Control Engine | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0(0)a5(2.0) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ace30 Application Control Engine Module | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.1(7.16) |
| Running on/with | Platform Versions |
|---|---|
Cisco Adaptive Security Appliance 5520 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.1(7.16) |
| Running on/with | Platform Versions |
|---|---|
Cisco Adaptive Security Appliance 5540 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.1(7.16) |
| Running on/with | Platform Versions |
|---|---|
Cisco Adaptive Security Appliance 5550 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.1(7.16) |
| Running on/with | Platform Versions |
|---|---|
Cisco Adaptive Security Appliance 5510 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.1(7.16) |
| Running on/with | Platform Versions |
|---|---|
Cisco Adaptive Security Appliance 5505 | All versions |
References (10)
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.