CVE Feed

    Dashboard / CVE / CVE-2019-1559

    CVE-2019-1559

    If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).

    Published:Feb 26, 2019
    Last Modified:Nov 21, 2024
    EPS:Feb 27, 2019
    EPSS Score:0.0708
    CVSS Score:5.9

    Affected Products

    Vendor
    Canonical
    Product
    Ubuntu Linux
    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    F5
    Product
    Big-ip Access Policy Manager
    Vendor
    F5
    Product
    Big-ip Advanced Firewall Manager
    Vendor
    F5
    Product
    Big-ip Analytics
    Vendor
    F5
    Product
    Big-ip Application Acceleration Manager
    Vendor
    F5
    Product
    Big-ip Application Security Manager
    Vendor
    F5
    Product
    Big-ip Domain Name System
    Vendor
    F5
    Product
    Big-ip Edge Gateway
    Vendor
    F5
    Product
    Big-ip Fraud Protection Service
    Vendor
    F5
    Product
    Big-ip Global Traffic Manager
    Vendor
    F5
    Product
    Big-ip Link Controller
    Vendor
    F5
    Product
    Big-ip Local Traffic Manager
    Vendor
    F5
    Product
    Big-ip Policy Enforcement Manager
    Vendor
    F5
    Product
    Big-ip Webaccelerator
    Vendor
    F5
    Product
    Big-iq Centralized Management
    Vendor
    F5
    Product
    Traffix Signaling Delivery Controller
    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Mcafee
    Product
    Agent
    Vendor
    Mcafee
    Product
    Data Exchange Layer
    Vendor
    Mcafee
    Product
    Threat Intelligence Exchange Server
    Vendor
    Mcafee
    Product
    Web Gateway
    Vendor
    Netapp
    Product
    A220
    Vendor
    Netapp
    Product
    A220 Firmware
    Vendor
    Netapp
    Product
    A320
    Vendor
    Netapp
    Product
    A320 Firmware
    Vendor
    Netapp
    Product
    A800
    Vendor
    Netapp
    Product
    A800 Firmware
    Vendor
    Netapp
    Product
    Active Iq Unified Manager
    Vendor
    Netapp
    Product
    Altavault
    Vendor
    Netapp
    Product
    C190
    Vendor
    Netapp
    Product
    C190 Firmware
    Vendor
    Netapp
    Product
    Cloud Backup
    Vendor
    Netapp
    Product
    Clustered Data Ontap Antivirus Connector
    Vendor
    Netapp
    Product
    Cn1610
    Vendor
    Netapp
    Product
    Cn1610 Firmware
    Vendor
    Netapp
    Product
    Element Software
    Vendor
    Netapp
    Product
    Fas2720
    Vendor
    Netapp
    Product
    Fas2720 Firmware
    Vendor
    Netapp
    Product
    Fas2750
    Vendor
    Netapp
    Product
    Fas2750 Firmware
    Vendor
    Netapp
    Product
    Hci Compute Node
    Vendor
    Netapp
    Product
    Hci Management Node
    Vendor
    Netapp
    Product
    Hyper Converged Infrastructure
    Vendor
    Netapp
    Product
    Oncommand Insight
    Vendor
    Netapp
    Product
    Oncommand Unified Manager
    Vendor
    Netapp
    Product
    Oncommand Unified Manager Core Package
    Vendor
    Netapp
    Product
    Oncommand Workflow Automation
    Vendor
    Netapp
    Product
    Ontap Select Deploy
    Vendor
    Netapp
    Product
    Ontap Select Deploy Administration Utility
    Vendor
    Netapp
    Product
    Santricity Smi-s Provider
    Vendor
    Netapp
    Product
    Service Processor
    Vendor
    Netapp
    Product
    Smi-s Provider
    Vendor
    Netapp
    Product
    Snapcenter
    Vendor
    Netapp
    Product
    Snapdrive
    Vendor
    Netapp
    Product
    Snapprotect
    Vendor
    Netapp
    Product
    Solidfire
    Vendor
    Netapp
    Product
    Steelstore Cloud Integrated Storage
    Vendor
    Netapp
    Product
    Storage Automation Store
    Vendor
    Netapp
    Product
    Storagegrid
    Vendor
    Nodejs
    Product
    Node.js
    Vendor
    Openssl
    Product
    Openssl
    Vendor
    Opensuse
    Product
    Leap
    Vendor
    Oracle
    Product
    Api Gateway
    Vendor
    Oracle
    Product
    Business Intelligence
    Vendor
    Oracle
    Product
    Communications Diameter Signaling Router
    Vendor
    Oracle
    Product
    Communications Performance Intelligence Center
    Vendor
    Oracle
    Product
    Communications Session Border Controller
    Vendor
    Oracle
    Product
    Communications Session Router
    Vendor
    Oracle
    Product
    Communications Unified Session Manager
    Vendor
    Oracle
    Product
    Endeca Server
    Vendor
    Oracle
    Product
    Enterprise Manager Base Platform
    Vendor
    Oracle
    Product
    Enterprise Manager Ops Center
    Vendor
    Oracle
    Product
    Jd Edwards Enterpriseone Tools
    Vendor
    Oracle
    Product
    Jd Edwards World Security
    Vendor
    Oracle
    Product
    Mysql
    Vendor
    Oracle
    Product
    Mysql Enterprise Monitor
    Vendor
    Oracle
    Product
    Mysql Workbench
    Vendor
    Oracle
    Product
    Peoplesoft Enterprise Peopletools
    Vendor
    Oracle
    Product
    Secure Global Desktop
    Vendor
    Oracle
    Product
    Services Tools Bundle
    Vendor
    Paloaltonetworks
    Product
    Pan-os
    Vendor
    Redhat
    Product
    Ansible Tower
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Enterprise Linux Desktop
    Vendor
    Redhat
    Product
    Enterprise Linux Server
    Vendor
    Redhat
    Product
    Enterprise Linux Workstation
    Vendor
    Redhat
    Product
    Jboss Enterprise Web Server
    Vendor
    Redhat
    Product
    Virtualization
    Vendor
    Redhat
    Product
    Virtualization Host
    Vendor
    Tenable
    Product
    Nessus

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High