// For flags

CVE-2018-0735

Timing attack against ECDSA signature generation

Severity Score

5.9
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).

Se ha demostrado que el algoritmo de firmas ECDSA en OpenSSL es vulnerable a un ataque de sincronización de canal lateral. Un atacante podría emplear variaciones en el algoritmo de firma para recuperar la clave privada. Se ha solucionado en OpenSSL 1.1.0j (afecta a 1.1.0-1.1.0i). Se ha solucionado en OpenSSL 1.1.1a (afecta a 1.1.1).

*Credits: Samuel Weiser
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-11-30 CVE Reserved
  • 2018-10-29 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-11-13 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-327: Use of a Broken or Risky Cryptographic Algorithm
  • CWE-385: Covert Timing Channel
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Netapp
Search vendor "Netapp"
Cn1610 Firmware
Search vendor "Netapp" for product "Cn1610 Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Cn1610
Search vendor "Netapp" for product "Cn1610"
--
Safe
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
>= 1.1.0 <= 1.1.0i
Search vendor "Openssl" for product "Openssl" and version " >= 1.1.0 <= 1.1.0i"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
1.1.1
Search vendor "Openssl" for product "Openssl" and version "1.1.1"
-
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
14.04
Search vendor "Canonical" for product "Ubuntu Linux" and version "14.04"
lts
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
16.04
Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04"
lts
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
18.04
Search vendor "Canonical" for product "Ubuntu Linux" and version "18.04"
lts
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
18.10
Search vendor "Canonical" for product "Ubuntu Linux" and version "18.10"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
8.0
Search vendor "Debian" for product "Debian Linux" and version "8.0"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
9.0
Search vendor "Debian" for product "Debian Linux" and version "9.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
>= 10.0.0 < 10.12.0
Search vendor "Nodejs" for product "Node.js" and version " >= 10.0.0 < 10.12.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
>= 11.0.0 < 11.3.0
Search vendor "Nodejs" for product "Node.js" and version " >= 11.0.0 < 11.3.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
10.13.0
Search vendor "Nodejs" for product "Node.js" and version "10.13.0"
lts
Affected
Netapp
Search vendor "Netapp"
Cloud Backup
Search vendor "Netapp" for product "Cloud Backup"
--
Affected
Netapp
Search vendor "Netapp"
Element Software
Search vendor "Netapp" for product "Element Software"
--
Affected
Netapp
Search vendor "Netapp"
Oncommand Unified Manager
Search vendor "Netapp" for product "Oncommand Unified Manager"
*-
Affected
Netapp
Search vendor "Netapp"
Oncommand Unified Manager
Search vendor "Netapp" for product "Oncommand Unified Manager"
>= 9.4
Search vendor "Netapp" for product "Oncommand Unified Manager" and version " >= 9.4"
vsphere
Affected
Netapp
Search vendor "Netapp"
Santricity Smi-s Provider
Search vendor "Netapp" for product "Santricity Smi-s Provider"
--
Affected
Netapp
Search vendor "Netapp"
Smi-s Provider
Search vendor "Netapp" for product "Smi-s Provider"
--
Affected
Netapp
Search vendor "Netapp"
Snapdrive
Search vendor "Netapp" for product "Snapdrive"
-unix
Affected
Netapp
Search vendor "Netapp"
Snapdrive
Search vendor "Netapp" for product "Snapdrive"
-windows
Affected
Netapp
Search vendor "Netapp"
Steelstore
Search vendor "Netapp" for product "Steelstore"
--
Affected
Oracle
Search vendor "Oracle"
Api Gateway
Search vendor "Oracle" for product "Api Gateway"
11.1.2.4.0
Search vendor "Oracle" for product "Api Gateway" and version "11.1.2.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Application Server
Search vendor "Oracle" for product "Application Server"
0.9.8
Search vendor "Oracle" for product "Application Server" and version "0.9.8"
-
Affected
Oracle
Search vendor "Oracle"
Application Server
Search vendor "Oracle" for product "Application Server"
1.0.0
Search vendor "Oracle" for product "Application Server" and version "1.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Application Server
Search vendor "Oracle" for product "Application Server"
1.0.1
Search vendor "Oracle" for product "Application Server" and version "1.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager Base Platform
Search vendor "Oracle" for product "Enterprise Manager Base Platform"
12.1.0.5.0
Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "12.1.0.5.0"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager Base Platform
Search vendor "Oracle" for product "Enterprise Manager Base Platform"
13.2.0.0.0
Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "13.2.0.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager Base Platform
Search vendor "Oracle" for product "Enterprise Manager Base Platform"
13.3.0.0.0
Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "13.3.0.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager Ops Center
Search vendor "Oracle" for product "Enterprise Manager Ops Center"
12.3.3
Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "12.3.3"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
<= 5.6.42
Search vendor "Oracle" for product "Mysql" and version " <= 5.6.42"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
>= 5.7.0 <= 5.7.24
Search vendor "Oracle" for product "Mysql" and version " >= 5.7.0 <= 5.7.24"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
>= 8.0.0 <= 8.0.13
Search vendor "Oracle" for product "Mysql" and version " >= 8.0.0 <= 8.0.13"
-
Affected
Oracle
Search vendor "Oracle"
Peoplesoft Enterprise Peopletools
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools"
8.55
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.55"
-
Affected
Oracle
Search vendor "Oracle"
Peoplesoft Enterprise Peopletools
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools"
8.56
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.56"
-
Affected
Oracle
Search vendor "Oracle"
Peoplesoft Enterprise Peopletools
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools"
8.57
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.57"
-
Affected
Oracle
Search vendor "Oracle"
Primavera P6 Enterprise Project Portfolio Management
Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management"
>= 17.7 <= 17.12
Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management" and version " >= 17.7 <= 17.12"
-
Affected
Oracle
Search vendor "Oracle"
Primavera P6 Enterprise Project Portfolio Management
Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management"
8.4
Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management" and version "8.4"
-
Affected
Oracle
Search vendor "Oracle"
Primavera P6 Enterprise Project Portfolio Management
Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management"
15.1
Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management" and version "15.1"
-
Affected
Oracle
Search vendor "Oracle"
Primavera P6 Enterprise Project Portfolio Management
Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management"
15.2
Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management" and version "15.2"
-
Affected
Oracle
Search vendor "Oracle"
Primavera P6 Enterprise Project Portfolio Management
Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management"
16.1
Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management" and version "16.1"
-
Affected
Oracle
Search vendor "Oracle"
Primavera P6 Enterprise Project Portfolio Management
Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management"
16.2
Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management" and version "16.2"
-
Affected
Oracle
Search vendor "Oracle"
Primavera P6 Enterprise Project Portfolio Management
Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management"
18.8
Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management" and version "18.8"
-
Affected
Oracle
Search vendor "Oracle"
Secure Global Desktop
Search vendor "Oracle" for product "Secure Global Desktop"
5.4
Search vendor "Oracle" for product "Secure Global Desktop" and version "5.4"
-
Affected
Oracle
Search vendor "Oracle"
Tuxedo
Search vendor "Oracle" for product "Tuxedo"
12.1.1.0.0
Search vendor "Oracle" for product "Tuxedo" and version "12.1.1.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Vm Virtualbox
Search vendor "Oracle" for product "Vm Virtualbox"
< 6.0.0
Search vendor "Oracle" for product "Vm Virtualbox" and version " < 6.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Vm Virtualbox
Search vendor "Oracle" for product "Vm Virtualbox"
>= 5.0.0 < 5.2.24
Search vendor "Oracle" for product "Vm Virtualbox" and version " >= 5.0.0 < 5.2.24"
-
Affected