The TLS implementation in the TCP/IP networking module in Unisys ClearPath MCP systems with TCP-IP-SW 58.1 before 58.160, 59.1 before 059.1a.17 (IC #17), and 60.0 before 60.044 might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
| Software | From | Fixed in |
|---|---|---|
| unisys / clearpath_mcp | 58.1 | 58.160 |
| unisys / clearpath_mcp | 59.1 | 059.1a.17 |
| unisys / clearpath_mcp | 60.0 | 60.044 |