You can use the Security Finder to search for security issues and their impact on Riverbed products. This
page is
continuously updated, displaying the most current public security issues first. The search box can be used to
look up
records by specific CVE numbers or relevant search word, e.g. Apache, 8.5.0, Workaround. For additional
search tips,
refer to article S16165. Security issues listed here are categorized into three groups: fixed, workaround recommended and not applicable.
For general security topics, security best practices and other security related topics, try performing a general search.
BETA FEATURE: This feature is currently under development and is considered Beta Software. We are still
enhancing the
features and results so please exercise caution when interpreting and implementing the results. If you have
any
questions, please open a case with Riverbed Support. If you have feedback for this tool, please send it to
supportfeedback@riverbed.com.
Riverbed Technology is committed to protecting customers against vulnerabilities in our supported products.
Vulnerabilities are addressed in accordance to the software support policy.
https://support.riverbed.com/content/support/about_support/end_of_life_policy.html
For search tips, read article S16165.
Details: A cross-protocol attack was discovered that could lead to decryption of TLS sessions by using a server supporting SSLv2 and EXPORT cipher suites as a Bleichenbacher RSA padding oracle. Note that traffic between clients and non-vulnerable servers can be decrypted provided another server supporting SSLv2 and EXPORT ciphers (even with a different protocol such as SMTP, IMAP or POP) shares the RSA keys of the non-vulnerable server. This vulnerability is known as DROWN (CVE-2016-0800). This update also includes patches for these lower priority CVEs: CVE-2016-0702, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, and CVE-2016-0798. For more details, see: https://www.openssl.org/news/secadv/20160301.txt and https://www.openssl.org/news/vulnerabilities.html#y2016. Note: SSLv2 is disabled on the appliances in the SteelHead and SteelFusion product line. This vulnerability is not applicable. This includes the web interface and the optimization service on the SteelHead appliance. Fix: OpenSSL upgraded to 1.0.2g or 1.0.1s where applicable. Note that the fix for CVE-2016-0800 disables SSLv2 and "EXPORT" and "LOW" strength ciphers. See https://www.openssl.org/news/secadv/20160301.txt. Recommendation: Upgrade the software to a version with this fix.