CVE-2018-0734Medium· 5.9▾ SunlitThe OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 2.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
12%
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).
openssl >= 1.0.2, <= 1.0.2popenssl >= 1.1.0, <= 1.1.0iopenssl = 1.1.1ubuntu_linux = 14.04ubuntu_linux = 16.04ubuntu_linux = 18.04ubuntu_linux = 18.10debian_linux = 9.0node.js >= 6.0.0, <= 6.8.1node.js >= 6.9.0, < 6.15.0node.js >= 8.0.0, <= 8.8.1node.js >= 8.9.0, < 8.14.0node.js >= 10.0.0, <= 10.12.0node.js >= 11.0.0, < 11.3.0node.js = 10.13.0cn1610_firmwarecloud_backuponcommand_unified_managersantricity_smi-s_providersnapcentersteelstorestorage_automation_storeapi_gateway = 11.1.2.4.0e-business_suite_technology_stack = 0.9.8e-business_suite_technology_stack = 1.0.0e-business_suite_technology_stack = 1.0.1enterprise_manager_base_platform = 12.1.0.5.0enterprise_manager_base_platform = 13.2.0.0.0enterprise_manager_base_platform = 13.3.0.0.0enterprise_manager_ops_center = 12.3.3mysql_enterprise_backup >= 3.0, <= 3.12.3mysql_enterprise_backup >= 4.0, <= 4.1.2peoplesoft_enterprise_peopletools = 8.55peoplesoft_enterprise_peopletools = 8.56peoplesoft_enterprise_peopletools = 8.57primavera_p6_professional_project_management >= 17.7, <= 17.12primavera_p6_professional_project_management = 8.4primavera_p6_professional_project_management = 15.1primavera_p6_professional_project_management = 15.2primavera_p6_professional_project_management = 16.1primavera_p6_professional_project_management = 16.2primavera_p6_professional_project_management = 18.8tuxedo = 12.1.1.0.0Upgrade past the affected range:
node.js 11.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2019-1563Low· 3.7In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption …
CVE-2018-0735Medium· 5.9The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack
CVE-2018-0732High· 7.5During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client
CVE-2021-3449Medium· 5.9An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client
CVE-2019-1551Medium· 5.3There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli
CVE-2021-3711Critical· 9.8In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt()