santricity_smi-s_provider vulnerabilities
CVEs whose affected-version data names the santricity_smi-s_provider package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2021-3711Critical· 9.8In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt()
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit…
CVE-2021-3449Medium· 5.9PoCAn OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHel…
CVE-2018-0734Medium· 5.9The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in…
CVE-2018-0735Medium· 5.9The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i).…