SECURITY ADVISORY – A10 Networks – #CVE-2014-8730 #CVE-2014-8730
#CVE-2014-8730 published on December 8th, 2014
Early in November, A10 Networks was notified of an issue with its implementation of TLS, which allows a padding oracle attack to be executed against it. The issue is in the way the protocol is implemented and that there is no proper padding checking in compliance with RFC 5246. This effectively introduces vulnerability similar to the one in SSLv3, where the padding is not defined as a part of the protocol specification – which opened CBC ciphers in SSLv3 to exploitation.
The vulnerability is assigned CVE-2014-8730 (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-8730).
In general, this bug can be exploited remotely – allowing an attacker to decrypt sensitive data in the SSL connection. At this point, there is no work around and it is necessary to apply the patches provided below.
Affected Platforms: ADC
Affected Software Versions: 2.6.1-GR1, 2.7.x
A10 Networks recommends upgrading to the latest available patch release:
Patches for the CVE-2014-3566 Poodle/SSL v3.0 vulnerability are here:
Trackbacks & Pingbacks
[…] SECURITY ADVISORY – A10 Networks – #CVE-2014-8730 #CVE-2014-8730 […]
Leave a ReplyWant to join the discussion?
Feel free to contribute!