<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 23:35:19 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-07080</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-07080</link>
      <description>bdu:2022-07080</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-07080</guid>
    </item>
    <item>
      <title>cisco-sa-ftd-tls-bb-rCgtmY2 — Cisco Firepower Threat Defense Software SSL Decryption Policy Bleichenbacher Attack Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-ftd-tls-bb-rcgtmy2</link>
      <description>&lt;p&gt;A vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain access to sensitive information.&#13;
&#13;
This vulnerability is due to improper implementation of countermeasures against a Bleichenbacher attack on a device that uses SSL decryption policies. An attacker could exploit this vulnerability by sending crafted TLS messages to an affected device, which would act as an oracle and allow the attacker to carry out a chosen-ciphertext attack. A successful exploit could allow the attacker to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions to the affected device.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of the November 2022 release of the Cisco ASA, FTD, and FMC Security Advisory Bundled publication. For a complete list of the advisories and links to them, see Cisco Event Response: November 2022 Semiannual Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication [&amp;#34;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-74838&amp;#34;].&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain access to sensitive information.&#13;
&#13;
This vulnerability is due to improper implementation of countermeasures against a Bleichenbacher attack on a device that uses SSL decryption policies. An attacker could exploit this vulnerability by sending crafted TLS messages to an affected device, which would act as an oracle and allow the attacker to carry out a chosen-ciphertext attack. A successful exploit could allow the attacker to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions to the affected device.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of the November 2022 release of the Cisco ASA, FTD, and FMC Security Advisory Bundled publication. For a complete list of the advisories and links to them, see Cisco Event Response: November 2022 Semiannual Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication [&amp;#34;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-74838&amp;#34;].&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-ftd-tls-bb-rcgtmy2</guid>
    </item>
    <item>
      <title>cnvd-2022-78142</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-78142</link>
      <description>cnvd-2022-78142</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-78142</guid>
    </item>
    <item>
      <title>EUVD-2026-13235</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-13235</link>
      <description>EUVD-2026-13235</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-13235</guid>
    </item>
    <item>
      <title>fkie_cve-2022-20940</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-20940</link>
      <description>&lt;p&gt;A vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain access to sensitive information.&#13;
&#13; This vulnerability is due to improper implementation of countermeasures against a Bleichenbacher attack on a device that uses SSL decryption policies. An attacker could exploit this vulnerability by sending crafted TLS messages to an affected device, which would act as an oracle and allow the attacker to carry out a chosen-ciphertext attack. A successful exploit could allow the attacker to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions to the affected device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain access to sensitive information.&#13;
&#13; This vulnerability is due to improper implementation of countermeasures against a Bleichenbacher attack on a device that uses SSL decryption policies. An attacker could exploit this vulnerability by sending crafted TLS messages to an affected device, which would act as an oracle and allow the attacker to carry out a chosen-ciphertext attack. A successful exploit could allow the attacker to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions to the affected device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-20940</guid>
    </item>
    <item>
      <title>GHSA-xqwj-v278-6v7x</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xqwj-v278-6v7x</link>
      <description>&lt;p&gt;A vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper implementation of countermeasures against a Bleichenbacher attack on a device that uses SSL decryption policies. An attacker could exploit this vulnerability by sending crafted TLS messages to an affected device, which would act as an oracle and allow the attacker to carry out a chosen-ciphertext attack. A successful exploit could allow the attacker to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions to the affected device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper implementation of countermeasures against a Bleichenbacher attack on a device that uses SSL decryption policies. An attacker could exploit this vulnerability by sending crafted TLS messages to an affected device, which would act as an oracle and allow the attacker to carry out a chosen-ciphertext attack. A successful exploit could allow the attacker to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions to the affected device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xqwj-v278-6v7x</guid>
    </item>
    <item>
      <title>gsd-2022-20940</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-20940</link>
      <description>gsd-2022-20940</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-20940</guid>
    </item>
  </channel>
</rss>
