Vulnerability Details CVE-2015-5738
The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS), makes it easier for remote attackers to obtain private RSA keys by conducting a Lenstra side-channel attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 73.8%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2015-5738
-
cpe:2.3:a:f5:traffix_signaling_delivery_controller:3.3.2
-
cpe:2.3:a:f5:traffix_signaling_delivery_controller:3.4.1
-
cpe:2.3:a:f5:traffix_signaling_delivery_controller:3.5.1
-
cpe:2.3:a:f5:traffix_signaling_delivery_controller:4.0.0
-
cpe:2.3:a:f5:traffix_signaling_delivery_controller:4.0.2
-
cpe:2.3:a:f5:traffix_signaling_delivery_controller:4.0.5
-
cpe:2.3:a:f5:traffix_signaling_delivery_controller:4.1.0
-
cpe:2.3:a:f5:traffix_signaling_delivery_controller:4.4.0
-
cpe:2.3:a:marvell:software_development_kit:2.0
-
cpe:2.3:h:marvell:octeon_ii_cn6000:-
-
cpe:2.3:h:marvell:octeon_ii_cn6010:-
-
cpe:2.3:h:marvell:octeon_ii_cn6020:-