CVE-2017-1000385 describes a Bleichenbacher-style oracle attack in the Erlang OTP TLS server, affecting Debian and Erlang/OTP distributions. This vulnerability allows an attacker to decrypt content or forge signatures by observing distinct TLS alert responses to different RSA PKCS #1 v1.5 padding errors. Rated Medium (CVSS 5.9), it has a high impact on confidentiality with high attack complexity, but does not affect integrity or availability. While not in CISA's KEV catalog, a Metasploit module exists, and it has garnered significant community discussion and media coverage, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
18.3.4.7CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/otp:18.3.4.7:*:*:*:*:*:*:* | ||
19.3.6.4CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/otp:19.3.6.4:*:*:*:*:*:*:* | ||
20.1.7CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/otp:20.1.7:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.