Security Finder

You can use the Security Finder to search for security issues and their impact on Riverbed products. This page is continuously updated, displaying the most current public security issues first. The search box can be used to look up records by specific CVE numbers or relevant search word, e.g. Apache, 8.5.0, Workaround. For additional search tips, refer to article S16165. Security issues listed here are categorized into three groups: fixed, workaround recommended and not applicable.

For general security topics, security best practices and other security related topics, try performing a general search.

BETA FEATURE: This feature is currently under development and is considered Beta Software. We are still enhancing the features and results so please exercise caution when interpreting and implementing the results. If you have any questions, please open a case with Riverbed Support. If you have feedback for this tool, please send it to supportfeedback@riverbed.com.

Riverbed Technology is committed to protecting customers against vulnerabilities in our supported products. Vulnerabilities are addressed in accordance to the software support policy. https://support.riverbed.com/content/support/about_support/end_of_life_policy.html

For search tips, read article S16165.

OpenSSL cumulative security update for advisory - secadv_20150319 (Bug #232135)

Product
SteelHead (Appliance)
Fixed in Version:
steelhead 9.0.1, steelhead 8.6.2c
Last Modified:
2016-08-19
Summary
Details:

This update addresses the following issues:

CVE-2015-0204: RSA silently downgrades to EXPORT_RSA [Client] (Re-classification)
CVE-2015-0207: Segmentation fault in DTLSv1_listen
CVE-2015-0208: Segmentation fault for invalid PSS parameters
CVE-2015-0209: Use After Free following d2i_ECPrivatekey error
CVE-2015-0285: Handshake with unseeded PRNG
CVE-2015-0286: Segmentation fault in ASN1_TYPE_cmp 
CVE-2015-0287: ASN.1 structure reuse memory corruption
CVE-2015-0288: X509_to_X509_REQ NULL pointer deref
CVE-2015-0289: PKCS7 NULL pointer dereferences 
CVE-2015-0290: Multiblock corrupted pointer 
CVE-2015-0291: OpenSSL 1.0.2 ClientHello sigalgs DoS
CVE-2015-0292: Base64 decode memory corruption
CVE-2015-0293: DoS via reachable assert in SSLv2 servers 
CVE-2015-1787: Empty CKE with client auth and DHE

For more information, see: http://openssl.org/news/secadv_20150319.txt

Fix:

Of the issues listed above, the following do not apply to the version of OpenSSL in RiOS:

CVE-2015-0207, CVE-2015-0208, CVE-2015-0285, CVE-2015-0290, CVE-2015-0291 & CVE-2015-1787

Of the remaining: 

CVE-2015-0204 is a client side vulnerability and doesn't impact RiOS management.

CVE-2015-0209 has minimal impact as RiOS management doesn’t receive Elliptic Curve private keys from untrusted sources.

CVE-2015-0286 impacts certificate-based client authentication, which RiOS management doesn't support.

CVE-2015-0287 has no impact on RiOS management, which doesn't rely on ASN.1 structure reuse.

CVE-2015-0288, CVE-2015-0289, & CVE-2015-0292 pose minimal risk as RiOS management only parses WebUI SSL certificates from authenticated users.

CVE-2015-0293 has no impact on RiOS management, which disables SSLv2 by default, and there is no option to enable it.
 
However, the OpenSSL library in RiOS management has been updated to a version that implicitly patches all the above issues.

Recommendation:

Upgrade to patched version if applicable.