A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE.
For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade edk2-ovmfUpgrade edk2-aarch64Upgrade edk2-toolsUpgrade openssl-perlUpgrade openssl-develUpgrade edk2-tools-docUpgrade openssl-libsUpgrade openssl | Mar 1, 2023 | Feb 8, 2023 |
| Alpine Linux | — | Upgrade opensslUpgrade openssl1.1-compatUpgrade openssl3 | Aug 22, 2024 | Feb 8, 2023 |
| Amazon Linux Ami 2 | — | Upgrade openssl11-staticUpgrade openssl-perlUpgrade openssl-debuginfoUpgrade openssl-libsUpgrade openssl-snapsafe-staticUpgrade edk2-ovmfUpgrade openssl11-debuginfoUpgrade edk2-aarch64Upgrade openssl-develUpgrade openssl-snapsafeUpgrade edk2-tools-docUpgrade openssl-staticUpgrade openssl-snapsafe-perlUpgrade openssl11-develUpgrade edk2-toolsUpgrade openssl-snapsafe-develUpgrade opensslUpgrade edk2-debuginfoUpgrade openssl-snapsafe-debuginfoUpgrade openssl11Upgrade openssl11-libsUpgrade edk2-tools-pythonUpgrade openssl-snapsafe-libs | Feb 9, 2023 | Feb 9, 2023 |
| Amazon_linux | — | Upgrade openssl | Feb 9, 2023 | Feb 7, 2023 |
| Amazon_linux_2023 | — | Upgrade openssl-libsUpgrade openssl-debuginfoUpgrade openssl-develUpgrade opensslUpgrade openssl-perlUpgrade openssl-libs-debuginfoUpgrade openssl-debugsource | Feb 17, 2025 | Feb 7, 2023 |
| Aruba Aos 10 | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | Apr 5, 2023 |
| Aruba Aos 8 | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | Apr 5, 2023 |
| Aruba Aos Cx | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Feb 24, 2025 | Apr 5, 2023 |
| Aruba Ecos | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Mar 17, 2025 | Apr 5, 2023 |
| Centos_linux | — | Upgrade openssl-debuginfoUpgrade openssl-develUpgrade openssl-debugsourceUpgrade openssl-libsUpgrade openssl-perlUpgrade edk2-ovmfUpgrade opensslUpgrade openssl-libs-debuginfo | Mar 1, 2023 | Feb 8, 2023 |
| Debian | — | Upgrade openssl | Feb 9, 2023 | Feb 9, 2023 |
| Dell Poweredge Dsa2023134 | — | Upgrade Dell PowerEdge to the latest version | Oct 23, 2025 | May 23, 2023 |
| Dell Poweredge Dsa2023207 | — | Upgrade Dell PowerEdge to the latest version | Oct 23, 2025 | Aug 21, 2023 |
| Dell Powerstore Dsa2023173 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jun 21, 2023 |
| Dell Powerstore Dsa2024158 | — | Upgrade Dell PowerStoreOS to the latest version | Jan 13, 2026 | Apr 4, 2024 |
| Dell Powerstore Dsa2024225 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | May 29, 2024 |
| Dell Powerstore Dsa2025086 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Feb 20, 2025 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 13, 2023 |
| Freebsd | — | Upgrade FreeBSDUpgrade openssl-develUpgrade opensslUpgrade openssl-quictls | Aug 31, 2023 | Aug 31, 2023 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Feb 5, 2024 | Feb 8, 2023 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Feb 8, 2023 | Feb 8, 2023 |
| Huawei Euleros 2_0_sp10 | — | Upgrade shim | May 18, 2023 | Feb 8, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade shim-aa64-storageUpgrade shim | Jul 5, 2023 | Feb 8, 2023 |
| Huawei Euleros 2_0_sp12 | — | Upgrade shimUpgrade shim-aa64-storage | Sep 15, 2025 | Apr 12, 2023 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openssl111dUpgrade openssl111d-staticUpgrade openssl111d-libsUpgrade openssl111d-devel | Jun 9, 2023 | Feb 8, 2023 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openssl-develUpgrade opensslUpgrade openssl-perlUpgrade openssl-libs | Apr 13, 2023 | Feb 8, 2023 |
| Huawei Euleros 2_0_sp9 | — | Upgrade opensslUpgrade openssl-perlUpgrade openssl-libs | May 10, 2023 | Feb 8, 2023 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory38 | Jul 27, 2023 | Feb 8, 2023 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Sep 4, 2023 |
| Oracle_linux | — | Upgrade edk2-ovmfUpgrade opensslUpgrade openssl-libsUpgrade OVMFUpgrade openssl-debugsourceUpgrade edk2-tools-docUpgrade edk2-toolsUpgrade openssl-perlUpgrade openssl-develUpgrade openssl-staticUpgrade edk2-aarch64Upgrade AAVMF | Mar 2, 2023 | Feb 7, 2023 |
| Redhat_linux | — | Upgrade edk2-tools-docUpgrade edk2-ovmfNo solution existsUpgrade edk2-aarch64Upgrade openssl-libsUpgrade openssl-perlUpgrade openssl-libs-debuginfoUpgrade edk2-toolsUpgrade edk2-debugsourceUpgrade openssl-debuginfoUpgrade openssl-develUpgrade openssl-debugsourceUpgrade edk2-tools-debuginfoUpgrade openssl | Mar 1, 2023 | Feb 8, 2023 |
| Rocky_linux | — | Upgrade openssl-debuginfoUpgrade openssl-perlUpgrade openssl-libsUpgrade openssl-develUpgrade openssl-debugsourceUpgrade opensslUpgrade openssl-libs-debuginfo | Mar 12, 2024 | Feb 8, 2023 |
| Sonicwall Sma 100 | — | Upgrade SonicWall SMA-100 to the latest version | Apr 3, 2023 | Feb 9, 2023 |
| Sonicwall Sonicos | — | Update SonicWall SonicOS Gen6 NSv to version 6.5.4.4-44v-21-2079 or laterUpdate SonicWall SonicOS Gen6 (TZ, NSA) to version 6.5.4.12-101n or later | Jun 12, 2026 | Feb 9, 2023 |
| Splunk | — | Upgrade Splunk Universal Forwarder to version 8.1.14Upgrade Splunk Universal Forwarder to version 9.0.5Upgrade Splunk Enterprise to version 9.0.5Upgrade Splunk Enterprise to version 8.2.11Upgrade Splunk Enterprise to version 8.1.14Upgrade Splunk Universal Forwarder to version 8.2.11 | Sep 30, 2025 | Feb 8, 2023 |
| Suse | — | Upgrade libopenssl3-32bitUpgrade openssl-1_0_0-cavsUpgrade openssl-1_1-docUpgrade openssl1-docUpgrade openssl-1_0_0Upgrade libopenssl-1_1-devel-32bitUpgrade libopenssl-develUpgrade libopenssl0_9_8-hmacUpgrade libopenssl-1_0_0-devel-32bitUpgrade libopenssl1_1-hmac-32bitUpgrade libopenssl1_1Upgrade openssl-3-docUpgrade libopenssl0_9_8-32bitUpgrade libopenssl-3-devel-32bitUpgrade libopenssl3Upgrade opensslUpgrade libopenssl1_0_0-steam-32bitUpgrade libopenssl-1_0_0-develUpgrade openssl-3Upgrade libopenssl0_9_8Upgrade libopenssl1-develUpgrade libopenssl0_9_8-hmac-32bitUpgrade libopenssl1_0_0-steamUpgrade libopenssl-3-develUpgrade libopenssl-1_1-develUpgrade libopenssl1_0_0Upgrade openssl1Upgrade libopenssl1_1-hmacUpgrade openssl-1_0_0-docUpgrade libopenssl1_0_0-hmac-32bitUpgrade libopenssl10Upgrade libopenssl1_0_0-hmacUpgrade libopenssl1_0_0-32bitUpgrade openssl-docUpgrade openssl-1_1Upgrade libopenssl1_1-32bit | Feb 8, 2023 | Feb 7, 2023 |
| Ubuntu | — | Upgrade qemu-efi-armUpgrade ovmfUpgrade libssl1.1Upgrade qemu-efi-riscv64Upgrade libnode-devUpgrade ovmf-ia32Upgrade qemu-efiUpgrade libssl3Upgrade qemu-efi-loongarch64Upgrade libnode72Upgrade qemu-efi-aarch64Upgrade nodejs | Mar 22, 2023 | Feb 8, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 8, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub