Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate attackers to obtain sensitive information by reading raw disk blocks.
References
Link | Resource |
---|---|
https://supportkb.riverbed.com/support/index?page=content&id=S30065 | Mitigation Vendor Advisory |
http://seclists.org/fulldisclosure/2017/Feb/25 | Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/96175 | Third Party Advisory VDB Entry |
https://sysdream.com/news/lab/2017-02-15-riverbed-rios-insecure-cryptographic-storage-cve-2017-5670/ |
Configurations
Information
Published : 2017-04-04 09:59
Updated : 2017-05-23 18:29
NVD link : CVE-2017-5670
Mitre link : CVE-2017-5670
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
riverbed
- rios