Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
Low
Attack Vector
Local
0

CVE-2017-14737

Disclosure Date: September 26, 2017
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array is indexed with bits derived from a secret key.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
5.5 Medium
Impact Score:
3.6
Exploitability Score:
1.8
Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
Low
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
None
Availability (A):
None

General Information

Vendors

  • botan project,
  • debian

Products

  • botan,
  • botan 1.11.0,
  • botan 1.11.1,
  • botan 1.11.10,
  • botan 1.11.11,
  • botan 1.11.12,
  • botan 1.11.13,
  • botan 1.11.14,
  • botan 1.11.15,
  • botan 1.11.16,
  • botan 1.11.17,
  • botan 1.11.18,
  • botan 1.11.19,
  • botan 1.11.2,
  • botan 1.11.20,
  • botan 1.11.21,
  • botan 1.11.22,
  • botan 1.11.23,
  • botan 1.11.24,
  • botan 1.11.25,
  • botan 1.11.26,
  • botan 1.11.27,
  • botan 1.11.28,
  • botan 1.11.3,
  • botan 1.11.33,
  • botan 1.11.34,
  • botan 1.11.4,
  • botan 1.11.5,
  • botan 1.11.6,
  • botan 1.11.7,
  • botan 1.11.8,
  • botan 1.11.9,
  • botan 2.0.0,
  • botan 2.0.1,
  • botan 2.1.0,
  • botan 2.2.0,
  • debian linux 9.0

Additional Info

Technical Analysis