Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate attackers to obtain sensitive information by reading raw disk blocks.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2017/Feb/25 | Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/96175 | Third Party Advisory VDB Entry |
https://supportkb.riverbed.com/support/index?page=content&id=S30065 | Mitigation Vendor Advisory |
https://sysdream.com/news/lab/2017-02-15-riverbed-rios-insecure-cryptographic-storage-cve-2017-5670/ | |
http://seclists.org/fulldisclosure/2017/Feb/25 | Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/96175 | Third Party Advisory VDB Entry |
https://supportkb.riverbed.com/support/index?page=content&id=S30065 | Mitigation Vendor Advisory |
https://sysdream.com/news/lab/2017-02-15-riverbed-rios-insecure-cryptographic-storage-cve-2017-5670/ |
Configurations
History
21 Nov 2024, 03:28
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2017/Feb/25 - Mailing List, Third Party Advisory | |
References | () http://www.securityfocus.com/bid/96175 - Third Party Advisory, VDB Entry | |
References | () https://supportkb.riverbed.com/support/index?page=content&id=S30065 - Mitigation, Vendor Advisory | |
References | () https://sysdream.com/news/lab/2017-02-15-riverbed-rios-insecure-cryptographic-storage-cve-2017-5670/ - |
Information
Published : 2017-04-04 16:59
Updated : 2024-11-21 03:28
NVD link : CVE-2017-5670
Mitre link : CVE-2017-5670
CVE.ORG link : CVE-2017-5670
JSON object : View
Products Affected
riverbed
- rios
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor