CVE-2018-0737

Advisory lineage Upstream: 0 Downstream: 26
Modified
Published: 16 Apr 2018, 17:00
Last modified:17 Sept 2024, 03:53

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
5.9 MEDIUM
v3.0 (nvd)
EPSS Score
38.12% HIGH
38% probability +1.03%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Apr 2018, 17:00
Published
Vulnerability first disclosed
17 Sept 2024, 03:53
Last Modified
Vulnerability information updated

Description

The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could recover the private key. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2b-1.0.2o).

CVSS Metrics

  • v3.0MEDIUMScore: 5.9CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 38.12% Percentile: 97%

Techniques & Countermeasures

  • CWE-327Use of a Broken or Risky Cryptographic Algorithm

    The product uses a broken or risky cryptographic algorithm or protocol.

Affected Systems

  • canonicalubuntu_linux

    14.04 | 16.04 | 17.10

  • UnknownOpenSSL

    ≥ 1.0.2b, ≤ 1.0.2o | ≥ 1.1.0, ≤ 1.1.0h | Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h) | Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2b-1.0.2o)

References (34)