Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate attackers to obtain sensitive information by reading raw disk blocks.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2017/Feb/25 | third party advisory mailing list |
https://sysdream.com/news/lab/2017-02-15-riverbed-rios-insecure-cryptographic-storage-cve-2017-5670/ | |
http://www.securityfocus.com/bid/96175 | vdb entry third party advisory |
https://supportkb.riverbed.com/support/index?page=content&id=S30065 | mitigation vendor advisory |