The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).
CVSS Details
- CVSS 3.0 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos Cx | — | The vulnerabilities contained in this advisory can be addressed
by patching or upgrading to one of the versions listed below
AOS-CX 10.06.xxxx: 10.06.0180 and above
AOS-CX 10.07.xxxx: 10.07.0061 and above
AOS-CX 10.08.xxxx: 10.08.1040 and above
AOS-CX 10.09.xxxx: 10.09.0010 and above
Aruba recommends that users using the following branches
upgrade to 10.06.0180 and above to address these vulnerabilities:
AOS-CX 10.05.xxxx and below
None of the above branch versions will address the UEFI
vulnerabilities mentioned in ARUBA-PSA-2022-001. | Feb 24, 2025 | Feb 22, 2022 |
| Debian | — | Upgrade erlang | Dec 8, 2017 | Dec 8, 2017 |
| Oracle Solaris | — | Upgrade runtime/erlang/documentation to version 21.0-11.4.6.0.1.1.0 on Solaris 11.4Upgrade runtime/erlang to version 21.0-11.4.6.0.1.1.0 on Solaris 11.4 | Feb 20, 2019 | Dec 12, 2017 |
| Suse | — | Upgrade erlang-jinterface-srcUpgrade erlangUpgrade erlang-gsUpgrade erlang-wxUpgrade erlang-srcUpgrade erlang-gs-srcUpgrade erlang-epmdUpgrade erlang-reltoolUpgrade erlang-reltool-srcUpgrade erlang-debugger-srcUpgrade erlang-observer-srcUpgrade erlang-wx-srcUpgrade erlang-docUpgrade erlang-diameterUpgrade erlang-jinterfaceUpgrade erlang-diameter-srcUpgrade erlang-et-srcUpgrade erlang-dialyzerUpgrade erlang-dialyzer-srcUpgrade erlang-observerUpgrade erlang-etUpgrade erlang-debugger | Dec 9, 2017 | Dec 8, 2017 |
| Ubuntu | — | Upgrade erlang | Feb 15, 2018 | Dec 8, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 12, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub