CVE-2015-5738

HIGH

Marvell Software Development Kit 2.x - RSA Private Key Exposure via Lenstra Side-Channel Attack

Title source: llm
STIX 2.1

Description

The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS), makes it easier for remote attackers to obtain private RSA keys by conducting a Lenstra side-channel attack.

References (3)

Core 3
Core References
Technical Description, Third Party Advisory x_refsource_misc
https://people.redhat.com/~fweimer/rsa-crt-leaks.pdf

Scores

CVSS v3 7.5
EPSS 0.0081
EPSS Percentile 74.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
f5/traffix_signaling_delivery_controller 3.3.2 - 3.5.1
marvell/software_development_kit 2.0
Published Jul 26, 2016
Tracked Since Feb 18, 2026