CVE-2017-17428 describes a Bleichenbacher RSA padding oracle vulnerability, also known as a ROBOT attack, affecting Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL SDKs, as well as Cisco products utilizing these SDKs. This medium-severity vulnerability (CVSS 5.9) allows remote attackers to decrypt TLS ciphertext data with high confidentiality impact, though it requires high attack complexity. While not currently on the CISA KEV catalog, a Metasploit scanner module exists, and the CVE has garnered some community discussion and media coverage, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.1.0CPE matchmatch criteria | cpe:2.3:a:cavium:nitrox_ssl_sdk:*:*:*:*:*:*:*:* | ||
<= 1.2CPE matchmatch criteria | cpe:2.3:a:cavium:nitrox_v_ssl_sdk:*:*:*:*:*:*:*:* | ||
<= 1.7.2CPE matchmatch criteria | cpe:2.3:a:cavium:octeon_sdk:*:*:*:*:*:*:*:* | ||
<= 1.5.0CPE matchmatch criteria | cpe:2.3:a:cavium:octeon_ssl_sdk:*:*:*:*:*:*:*:* | ||
<= 1.0CPE matchmatch criteria | cpe:2.3:a:cavium:turbossl_sdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.