The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).
CVSS Details
- CVSS 3.0 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos Cx | — | The vulnerabilities contained in this advisory can be addressed
by patching or upgrading to one of the versions listed below
AOS-CX 10.06.xxxx: 10.06.0180 and above
AOS-CX 10.07.xxxx: 10.07.0061 and above
AOS-CX 10.08.xxxx: 10.08.1040 and above
AOS-CX 10.09.xxxx: 10.09.0010 and above
Aruba recommends that users using the following branches
upgrade to 10.06.0180 and above to address these vulnerabilities:
AOS-CX 10.05.xxxx and below
None of the above branch versions will address the UEFI
vulnerabilities mentioned in ARUBA-PSA-2022-001. | Feb 24, 2025 | Feb 22, 2022 |
| Debian | — | Upgrade erlang | Dec 8, 2017 | Dec 8, 2017 |
| Oracle Solaris | — | Upgrade runtime/erlang/documentation to version 21.0-11.4.6.0.1.1.0 on Solaris 11.4Upgrade runtime/erlang to version 21.0-11.4.6.0.1.1.0 on Solaris 11.4 | Feb 20, 2019 | Dec 12, 2017 |
| Suse | — | Upgrade erlang-docUpgrade erlang-debugger-srcUpgrade erlang-reltool-srcUpgrade erlang-reltoolUpgrade erlang-wx-srcUpgrade erlang-gs-srcUpgrade erlang-wxUpgrade erlang-gsUpgrade erlang-srcUpgrade erlang-observer-srcUpgrade erlang-epmdUpgrade erlangUpgrade erlang-jinterface-srcUpgrade erlang-etUpgrade erlang-diameter-srcUpgrade erlang-et-srcUpgrade erlang-diameterUpgrade erlang-observerUpgrade erlang-debuggerUpgrade erlang-dialyzerUpgrade erlang-jinterfaceUpgrade erlang-dialyzer-src | Dec 9, 2017 | Dec 8, 2017 |
| Ubuntu | — | Upgrade erlang | Feb 15, 2018 | Dec 8, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 12, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub