CVE-2018-0735

Modified
Published: 29 Oct 2018, 13:00
Last modified:16 Sept 2024, 19:10

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
5.9 MEDIUM
v3.1 (nvd)
EPSS Score
4.8% LOW
5% probability -2.24%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

29 Oct 2018, 13:00
Published
Vulnerability first disclosed
16 Sept 2024, 19:10
Last Modified
Vulnerability information updated

Description

The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).

CVSS Metrics

  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 4.80% Percentile: 90%

Techniques & Countermeasures

  • CWE-327Use of a Broken or Risky Cryptographic Algorithm

    The product uses a broken or risky cryptographic algorithm or protocol.

Affected Systems

  • canonicalubuntu_linux

    14.04 | 16.04 | 18.04 | 18.10

  • debiandebian_linux

    8.0 | 9.0

  • netappcloud_backup

    na

  • netappcn1610_firmware

    na

  • netappelement_software

    na

  • netapponcommand_unified_manager

    ≥ 9.4

  • netappsantricity_smi-s_provider

    na

  • netappsmi-s_provider

    na

  • netappsnapdrive

    na

  • netappsteelstore

    na

  • nodejsnode.js

    ≥ 10.0.0, < 10.12.0 | ≥ 11.0.0, < 11.3.0 | 10.13.0

  • UnknownOpenSSL

    ≥ 1.1.0, ≤ 1.1.0i | 1.1.1 | Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i) | Fixed in OpenSSL 1.1.1a (Affected 1.1.1)

  • oracleapi_gateway

    11.1.2.4.0

  • oracleapplication_server

    0.9.8 | 1.0.0 | 1.0.1

  • oracleenterprise_manager_base_platform

    12.1.0.5.0 | 13.2.0.0.0 | 13.3.0.0.0

  • oracleenterprise_manager_ops_center

    12.3.3

  • oraclemysql

    ≤ 5.6.42 | ≥ 5.7.0, ≤ 5.7.24 | ≥ 8.0.0, ≤ 8.0.13

  • oraclepeoplesoft_enterprise_peopletools

    8.55 | 8.56 | 8.57

  • oracleprimavera_p6_enterprise_project_portfolio_management

    ≥ 17.7, ≤ 17.12 | 8.4 | 15.1 | 15.2 | 16.1 | 16.2 | 18.8

  • oraclesecure_global_desktop

    5.4

  • oracletuxedo

    12.1.1.0.0

  • oraclevm_virtualbox

    < 6.0.0 | ≥ 5.0.0, < 5.2.24

References (15)