BDU:2021-03037
Средний уровень опасности (базовая оценка CVSS 2.0 составляет 4,3) Средний уровень опасности (базовая оценка CVSS 3.0 составляет 5,9) CVSS 5.900000095367432 · AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NУязвимость процедуры AVX2 Montgomery библиотеки OpenSSL, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Отчёты сканеров говорят на языке CVE, требования регуляторов — на языке БДУ. Перевести список из отчёта →
Описание
Уязвимость процедуры AVX2 Montgomery библиотеки OpenSSL связана с недостатками защиты служебных данных. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, получить несанкционированный доступ к защищаемой информации с помощью закрытого ключа DH1024
Способ устранения
Использование рекомендаций: Для OpenSSL: https://www.openssl.org/news/secadv/20171207.txt https://www.openssl.org/news/secadv/20180327.txt Для Node.js: https://nodejs.org/en/blog/vulnerability/december-2017-security-releases/ Для Debian GNU/Linux: https://www.debian.org/security/2017/dsa-4065 https://www.debian.org/security/2018/dsa-4157 Для программных продуктов Red Hat Inc.: https://access.redhat.com/security/cve/cve-2017-3738 Для Ubuntu: https://ubuntu.com/security/notices/USN-3512-1 Для программных продуктов Oracle Corp.: http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Сведения записи
Уязвимое программное обеспечение
| Производитель | Название | Версия | Платформа |
|---|---|---|---|
| Canonical Ltd. | Ubuntu | 16.04 ESM | Не указана |
| Canonical Ltd. | Ubuntu | 17.04 | Не указана |
| Canonical Ltd. | Ubuntu | 17.10 | Не указана |
| IBM Corp. | Communications Session Border Controller | SCz7.4.0 | Не указана |
| IBM Corp. | Communications Session Border Controller | SCz7.4.1 | Не указана |
| IBM Corp. | Communications Session Border Controller | SCz8.0.0 | Не указана |
| IBM Corp. | Communications Session Border Controller | SCz8.1.0 | Не указана |
| Node.js Foundation | Node.js | 4 | Не указана |
| Node.js Foundation | Node.js | 6 | Не указана |
| Node.js Foundation | Node.js | 8 | Не указана |
| Node.js Foundation | Node.js | 9 | Не указана |
| OpenSSL Software Foundation | OpenSSL | от 1.0.2 до 1.0.2n | Не указана |
| OpenSSL Software Foundation | OpenSSL | от 1.1.0 до 1.1.0h | Не указана |
| Oracle Corp. | API Gateway | 11.1.2.4.0 | Не указана |
| Oracle Corp. | Agile Engineering Data Management | 6.1.3 | Не указана |
| Oracle Corp. | Agile Engineering Data Management | 6.2.0 | Не указана |
| Oracle Corp. | Agile Engineering Data Management | 6.2.1 | Не указана |
| Oracle Corp. | Communications Application Session Controller | 3.7.1 | Не указана |
| Oracle Corp. | Communications Application Session Controller | 3.8.0 | Не указана |
| Oracle Corp. | Communications Diameter Signaling Router | 8.0 | Не указана |
| Oracle Corp. | Communications Diameter Signaling Router | 8.1 | Не указана |
| Oracle Corp. | Communications Diameter Signaling Router | 8.2 | Не указана |
| Oracle Corp. | Communications Diameter Signaling Router | 8.3 | Не указана |
| Oracle Corp. | Communications EAGLE LNP Application Processor | 10.0 | Не указана |
| Oracle Corp. | Communications EAGLE LNP Application Processor | 10.1 | Не указана |
| Oracle Corp. | Communications EAGLE LNP Application Processor | 10.2 | Не указана |
| Oracle Corp. | Communications EAGLE Software | 46.5 | Не указана |
| Oracle Corp. | Communications EAGLE Software | 46.6 | Не указана |
| Oracle Corp. | Communications EAGLE Software | 46.7 | Не указана |
| Oracle Corp. | Communications Network Charging and Control | 4.4.1.5.0 | Не указана |
| Oracle Corp. | Communications Network Charging and Control | 5.0.0.1.0 | Не указана |
| Oracle Corp. | Communications Network Charging and Control | 5.0.0.2.0 | Не указана |
| Oracle Corp. | Communications Network Charging and Control | 5.0.1.0.0 | Не указана |
| Oracle Corp. | Communications Network Charging and Control | 5.0.2.0.0 | Не указана |
| Oracle Corp. | Communications Operations Monitor | 3.4 | Не указана |
| Oracle Corp. | Communications Operations Monitor | 4.0 | Не указана |
| Oracle Corp. | Communications Unified Session Manager | SCz7.3.5 | Не указана |
| Oracle Corp. | Communications WebRTC Session Controller | до 7.2 | Не указана |
| Oracle Corp. | Endeca Server | 7.6.1 | Не указана |
| Oracle Corp. | Endeca Server | 7.7.0 | Не указана |
| Oracle Corp. | Enterprise Communications Broker | PCz2.1 | Не указана |
| Oracle Corp. | Enterprise Communications Broker | PCz2.2 | Не указана |
| Oracle Corp. | Enterprise Communications Broker | PCz3.0 | Не указана |
| Oracle Corp. | Enterprise Manager Base Platform | 12.1.0.5 | Не указана |
| Oracle Corp. | Enterprise Manager Base Platform | 13.2.0.0 | Не указана |
| Oracle Corp. | Enterprise Manager Base Platform | 13.3.0.0 | Не указана |
| Oracle Corp. | Enterprise Manager Ops Center | 12.2.2 | Не указана |
| Oracle Corp. | Enterprise Manager Ops Center | 12.3.3 | Не указана |
| Oracle Corp. | Enterprise Session Border Controller | ECz7.4.0 | Не указана |
| Oracle Corp. | Enterprise Session Border Controller | ECz7.5.0 | Не указана |
Показано 50 из 91 записей — полный перечень в первоисточнике.
Чтобы такие записи находились не вручную, ведите реестр программного обеспечения: в личном кабинете уязвимости сопоставляются с вашим ПО, а работы по устранению попадают в план. Завести кабинет →
Источник: Банк данных угроз безопасности информации ФСТЭК России. Данные выгружены 17.08.2026, записей в справочнике — 92920. Справочник не является официальным ресурсом ФСТЭК России: сверяйте сведения с первоисточником.