{"id":"CVE-2018-0735","title":"The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack","summary":"The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i).…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-327"],"vendor":"openssl","product":"openssl","affected":["openssl >= 1.1.0, <= 1.1.0i","openssl = 1.1.1","ubuntu_linux = 14.04","ubuntu_linux = 16.04","ubuntu_linux = 18.04","ubuntu_linux = 18.10","debian_linux = 8.0","debian_linux = 9.0","node.js >= 10.0.0, < 10.12.0","node.js >= 11.0.0, < 11.3.0","node.js = 10.13.0","cn1610_firmware","cloud_backup","element_software","oncommand_unified_manager","oncommand_unified_manager >= 9.4","santricity_smi-s_provider","smi-s_provider","snapdrive","steelstore","api_gateway = 11.1.2.4.0","application_server = 0.9.8","application_server = 1.0.0","application_server = 1.0.1","enterprise_manager_base_platform = 12.1.0.5.0","enterprise_manager_base_platform = 13.2.0.0.0","enterprise_manager_base_platform = 13.3.0.0.0","enterprise_manager_ops_center = 12.3.3","mysql <= 5.6.42","mysql >= 5.7.0, <= 5.7.24","mysql >= 8.0.0, <= 8.0.13","peoplesoft_enterprise_peopletools = 8.55","peoplesoft_enterprise_peopletools = 8.56","peoplesoft_enterprise_peopletools = 8.57","primavera_p6_enterprise_project_portfolio_management >= 17.7, <= 17.12","primavera_p6_enterprise_project_portfolio_management = 8.4","primavera_p6_enterprise_project_portfolio_management = 15.1","primavera_p6_enterprise_project_portfolio_management = 15.2","primavera_p6_enterprise_project_portfolio_management = 16.1","primavera_p6_enterprise_project_portfolio_management = 16.2","primavera_p6_enterprise_project_portfolio_management = 18.8","secure_global_desktop = 5.4","tuxedo = 12.1.1.0.0","vm_virtualbox < 6.0.0","vm_virtualbox >= 5.0.0, < 5.2.24"],"patched":["node.js 11.3.0","vm_virtualbox 5.2.24"],"published":"2018-10-29","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:16:43.880","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-0735","references":[{"url":"http://www.securityfocus.com/bid/105750","label":"openssl-security@openssl.org"},{"url":"http://www.securitytracker.com/id/1041986","label":"openssl-security@openssl.org"},{"url":"https://access.redhat.com/errata/RHSA-2019:3700","label":"openssl-security@openssl.org"},{"url":"https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=56fb454d281a023b3f950d969693553d3f3ceea1","label":"openssl-security@openssl.org"},{"url":"https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=b1d6d55ece1c26fa2829e2b819b038d7b6d692b4","label":"openssl-security@openssl.org"},{"url":"https://lists.debian.org/debian-lts-announce/2018/11/msg00024.html","label":"openssl-security@openssl.org"},{"url":"https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/","label":"openssl-security@openssl.org"},{"url":"https://security.netapp.com/advisory/ntap-20181105-0002/","label":"openssl-security@openssl.org"},{"url":"https://usn.ubuntu.com/3840-1/","label":"openssl-security@openssl.org"},{"url":"https://www.debian.org/security/2018/dsa-4348","label":"openssl-security@openssl.org"},{"url":"https://www.openssl.org/news/secadv/20181029.txt","label":"openssl-security@openssl.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2020.html","label":"openssl-security@openssl.org"},{"url":"https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","label":"openssl-security@openssl.org"},{"url":"https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","label":"openssl-security@openssl.org"},{"url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","label":"openssl-security@openssl.org"},{"url":"http://www.securityfocus.com/bid/105750","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securitytracker.com/id/1041986","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2019:3700","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=56fb454d281a023b3f950d969693553d3f3ceea1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=b1d6d55ece1c26fa2829e2b819b038d7b6d692b4","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2018/11/msg00024.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20181105-0002/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/3840-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2018/dsa-4348","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.openssl.org/news/secadv/20181029.txt","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.04724,"epssPercentile":0.91602,"ingestedAt":"2026-10-08T23:16:47.293Z","slug":"CVE-2018-0735","body":"## Overview\n\nThe OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).\n\n## Affected\n\n- `openssl >= 1.1.0, <= 1.1.0i`\n- `openssl = 1.1.1`\n- `ubuntu_linux = 14.04`\n- `ubuntu_linux = 16.04`\n- `ubuntu_linux = 18.04`\n- `ubuntu_linux = 18.10`\n- `debian_linux = 8.0`\n- `debian_linux = 9.0`\n- `node.js >= 10.0.0, < 10.12.0`\n- `node.js >= 11.0.0, < 11.3.0`\n- `node.js = 10.13.0`\n- `cn1610_firmware`\n- `cloud_backup`\n- `element_software`\n- `oncommand_unified_manager`\n- `oncommand_unified_manager >= 9.4`\n- `santricity_smi-s_provider`\n- `smi-s_provider`\n- `snapdrive`\n- `steelstore`\n- `api_gateway = 11.1.2.4.0`\n- `application_server = 0.9.8`\n- `application_server = 1.0.0`\n- `application_server = 1.0.1`\n- `enterprise_manager_base_platform = 12.1.0.5.0`\n- `enterprise_manager_base_platform = 13.2.0.0.0`\n- `enterprise_manager_base_platform = 13.3.0.0.0`\n- `enterprise_manager_ops_center = 12.3.3`\n- `mysql <= 5.6.42`\n- `mysql >= 5.7.0, <= 5.7.24`\n- `mysql >= 8.0.0, <= 8.0.13`\n- `peoplesoft_enterprise_peopletools = 8.55`\n- `peoplesoft_enterprise_peopletools = 8.56`\n- `peoplesoft_enterprise_peopletools = 8.57`\n- `primavera_p6_enterprise_project_portfolio_management >= 17.7, <= 17.12`\n- `primavera_p6_enterprise_project_portfolio_management = 8.4`\n- `primavera_p6_enterprise_project_portfolio_management = 15.1`\n- `primavera_p6_enterprise_project_portfolio_management = 15.2`\n- `primavera_p6_enterprise_project_portfolio_management = 16.1`\n- `primavera_p6_enterprise_project_portfolio_management = 16.2`\n- `primavera_p6_enterprise_project_portfolio_management = 18.8`\n- `secure_global_desktop = 5.4`\n- `tuxedo = 12.1.1.0.0`\n- `vm_virtualbox < 6.0.0`\n- `vm_virtualbox >= 5.0.0, < 5.2.24`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `node.js 11.3.0`\n- `vm_virtualbox 5.2.24`","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":32.5,"likelihood":0.9,"exploitation":0,"ransomware":0},"changes":[]}