Lucene search

K
nvd[email protected]NVD:CVE-2018-0735
HistoryOct 29, 2018 - 1:29 p.m.

CVE-2018-0735

2018-10-2913:29:00
CWE-327
web.nvd.nist.gov
1

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

5.7 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.5%

The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).

Affected configurations

NVD
Node
opensslopensslRange1.1.01.1.0i
OR
opensslopensslMatch1.1.1
Node
canonicalubuntu_linuxMatch14.04lts
OR
canonicalubuntu_linuxMatch16.04lts
OR
canonicalubuntu_linuxMatch18.04lts
OR
canonicalubuntu_linuxMatch18.10
Node
debiandebian_linuxMatch8.0
OR
debiandebian_linuxMatch9.0
Node
nodejsnode.jsRange10.0.010.12.0-
OR
nodejsnode.jsRange11.0.011.3.0-
OR
nodejsnode.jsMatch10.13.0lts
Node
netappcn1610_firmwareMatch-
AND
netappcn1610Match-
Node
netappcloud_backupMatch-
OR
netappelement_softwareMatch-
OR
netapponcommand_unified_manager
OR
netapponcommand_unified_managerRange9.4vsphere
OR
netappsantricity_smi-s_providerMatch-
OR
netappsmi-s_providerMatch-
OR
netappsnapdriveMatch-unix
OR
netappsnapdriveMatch-windows
OR
netappsteelstoreMatch-
Node
oracleapi_gatewayMatch11.1.2.4.0
OR
oracleapplication_serverMatch0.9.8
OR
oracleapplication_serverMatch1.0.0
OR
oracleapplication_serverMatch1.0.1
OR
oracleenterprise_manager_base_platformMatch12.1.0.5.0
OR
oracleenterprise_manager_base_platformMatch13.2.0.0.0
OR
oracleenterprise_manager_base_platformMatch13.3.0.0.0
OR
oracleenterprise_manager_ops_centerMatch12.3.3
OR
oraclemysqlRange5.6.42
OR
oraclemysqlRange5.7.05.7.24
OR
oraclemysqlRange8.0.08.0.13
OR
oraclepeoplesoft_enterprise_peopletoolsMatch8.55
OR
oraclepeoplesoft_enterprise_peopletoolsMatch8.56
OR
oraclepeoplesoft_enterprise_peopletoolsMatch8.57
OR
oracleprimavera_p6_enterprise_project_portfolio_managementRange17.717.12
OR
oracleprimavera_p6_enterprise_project_portfolio_managementMatch8.4
OR
oracleprimavera_p6_enterprise_project_portfolio_managementMatch15.1
OR
oracleprimavera_p6_enterprise_project_portfolio_managementMatch15.2
OR
oracleprimavera_p6_enterprise_project_portfolio_managementMatch16.1
OR
oracleprimavera_p6_enterprise_project_portfolio_managementMatch16.2
OR
oracleprimavera_p6_enterprise_project_portfolio_managementMatch18.8
OR
oraclesecure_global_desktopMatch5.4
OR
oracletuxedoMatch12.1.1.0.0
OR
oraclevm_virtualboxRange<6.0.0
OR
oraclevm_virtualboxRange5.0.05.2.24

References

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

5.7 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.5%