ZeroHour

CVE-2017-17428

CVSS 3.0
5.9 medium
EPSS
15%p96
Published
()
Modified
Description

Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.

Vendors
caviumcisco
Products
nitrox ssl sdk, nitrox v ssl sdk, octeon sdk, octeon ssl sdk, turbossl sdk, webex conect im, webex meetings, ace4710 application control engine firmware, ace30 application control engine module firmware, adaptive security appliance 5520 firmware, adaptive security appliance 5540 firmware, adaptive security appliance 5550 firmware
Weakness
CWE-327
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news