CVE-2015-5738: F5 Traffix Signaling Delivery Controller

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS), makes it easier for remote attackers to obtain private RSA keys by conducting a Lenstra side-channel attack.

Affected products

  • F5 Traffix Signaling Delivery Controller: from 3.3.2, up to and including 3.5.1; from 4.0.0, up to and including 4.4.0
  • Marvell Software Development Kit: version 2.0 only

Published 2016-07-26. Last modified 2026-06-17.