SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-10845

It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack.

MEDIUM 5.9EPSS 3.62%

Does this matter?

Lower severity and a low EPSS score (3.62%). Track it; it rarely justifies an emergency change on its own.

Description

It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
3.62% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-385, CWE-327
Affected
gnu/gnutls · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation · canonical/ubuntu linux · fedoraproject/fedora · debian/debian linux
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.