PT-2016-3065 · Cavium+1 · Cavium Software Development Kit+2

Published

2016-07-26

·

Updated

2024-06-15

·

CVE-2015-5738

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cavium Software Development Kit (SDK) versions 2.x
Description The issue is related to the RSA-CRT implementation in the Cavium Software Development Kit (SDK), which lacks protection of service data. This makes it easier for remote attackers to obtain private RSA keys by conducting a side-channel attack, specifically a Lenstra side-channel attack, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS).
Recommendations For Cavium Software Development Kit (SDK) versions 2.x, consider disabling the use of RSA-CRT implementation until a patch is available to prevent remote attackers from obtaining private RSA keys. Restrict access to the TLS functionality with Perfect Forward Secrecy (PFS) to minimize the risk of exploitation. Avoid using the affected SDK version on OCTEON II CN6xxx Hardware on Linux until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-00287
CVE-2015-5738
OPENSUSE-SU-2024:10037-1

Affected Products

Cavium Software Development Kit
Linux
Octeon Ii Cn6Xxx