VulnerabilityModified
CVE-2017-5670
Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate attackers to obtain sensitive information by reading raw disk blocks.
MEDIUM 4.6EPSS 0.42%
Does this matter?
Lower severity and a low EPSS score (0.42%). Track it; it rarely justifies an emergency change on its own.
Description
Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate attackers to obtain sensitive information by reading raw disk blocks.
- CVSS 3.0
- 4.6 MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.42% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- riverbed/rios
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2017/Feb/25Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/96175Third Party Advisory, VDB Entry
- https://supportkb.riverbed.com/support/index?page=content&id=S30065Mitigation, Vendor Advisory
- https://sysdream.com/news/lab/2017-02-15-riverbed-rios-insecure-cryptographic-storage-cve-2017-5670/
- http://seclists.org/fulldisclosure/2017/Feb/25Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/96175Third Party Advisory, VDB Entry
- https://supportkb.riverbed.com/support/index?page=content&id=S30065Mitigation, Vendor Advisory
- https://sysdream.com/news/lab/2017-02-15-riverbed-rios-insecure-cryptographic-storage-cve-2017-5670/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.