Security Finder

You can use the Security Finder to search for security issues and their impact on Riverbed products. This page is continuously updated, displaying the most current public security issues first. The search box can be used to look up records by specific CVE numbers or relevant search word, e.g. Apache, 8.5.0, Workaround. For additional search tips, refer to article S16165. Security issues listed here are categorized into three groups: fixed, workaround recommended and not applicable.

For general security topics, security best practices and other security related topics, try performing a general search.

BETA FEATURE: This feature is currently under development and is considered Beta Software. We are still enhancing the features and results so please exercise caution when interpreting and implementing the results. If you have any questions, please open a case with Riverbed Support. If you have feedback for this tool, please send it to supportfeedback@riverbed.com.

Riverbed Technology is committed to protecting customers against vulnerabilities in our supported products. Vulnerabilities are addressed in accordance to the software support policy. https://support.riverbed.com/content/support/about_support/end_of_life_policy.html

For search tips, read article S16165.

OpenSSL 1.0.2g/1.0.1s security update including CVE-2016-0800 SSL/TLS: Cross-protocol attack on TLS using SSLv2 (DROWN) (Bug #253260)

Products:
SteelHead (Appliance), SteelHead Interceptor, SteelCentral Controller for SteelHead (Central Management Console)
Fixed in Version:
steelhead 9.1.2a, interceptor 5.5.0, cmc 9.2.0, steelhead 9.2.0
Last Modified:
2016-08-05
Summary
Details:

A cross-protocol attack was discovered that could lead to decryption of TLS sessions by using a server supporting SSLv2 and EXPORT cipher suites as a Bleichenbacher RSA padding oracle. Note that traffic between clients and non-vulnerable servers can be decrypted provided another server supporting SSLv2 and EXPORT ciphers (even with a different protocol such as SMTP, IMAP or POP) shares the RSA keys of the non-vulnerable server. This vulnerability is known as DROWN (CVE-2016-0800).

This update also includes patches for these lower priority CVEs: CVE-2016-0702, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, and CVE-2016-0798.

For more details, see:  https://www.openssl.org/news/secadv/20160301.txt and https://www.openssl.org/news/vulnerabilities.html#y2016.

Note: SSLv2 is disabled on the appliances in the SteelHead and SteelFusion product line.  This vulnerability is not applicable. This includes the web interface and the optimization service on the SteelHead appliance.

Fix:

OpenSSL upgraded to 1.0.2g or 1.0.1s where applicable.  Note that the fix for CVE-2016-0800 disables SSLv2 and "EXPORT" and "LOW" strength ciphers.  See https://www.openssl.org/news/secadv/20160301.txt.

Recommendation:

Upgrade the software to a version with this fix.