Lucene search

K
f5F5F5:K10281096
HistoryJan 07, 2019 - 12:00 a.m.

K10281096 : TLS in Mozilla NSS vulnerability CVE-2018-12404

2019-01-0700:00:00
my.f5.com
15

5.8 Medium

AI Score

Confidence

High

0.102 Low

EPSS

Percentile

95.0%

Security Advisory Description

A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) and affects all NSS versions prior to NSS 3.41. (CVE-2018-12404)

Impact

Traffix SDC

As a variant of the Bleichenbacher attack, the attacker may exploit this vulnerability to perform plaintext recovery of encrypted messages and read the plaintext only after the session has completed, potentially resulting in information leakage.

BIG-IP, BIG-IQ, Enterprise Manager, and F5 iWorkflow

There is no impact; these F5 products are not affected by this vulnerability.