5

CVE-2015-2808

The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OracleHTTP Server Version11.1.1.7.0
OracleHTTP Server Version11.1.1.9.0
OracleHTTP Server Version12.1.3.0.0
OracleHTTP Server Version12.2.1.1.0
OracleHTTP Server Version12.2.1.2.0
OracleIntegrated Lights Out Manager Firmware Version >= 3.0.0 <= 3.2.11
OracleIntegrated Lights Out Manager Firmware Version >= 4.0.0 <= 4.0.4
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
RedhatSatellite Version5.7
RedhatEnterprise Linux Eus Version6.6
RedhatEnterprise Linux Eus Version7.1
RedhatEnterprise Linux Eus Version7.2
RedhatEnterprise Linux Eus Version7.3
RedhatEnterprise Linux Eus Version7.4
RedhatEnterprise Linux Eus Version7.5
RedhatEnterprise Linux Eus Version7.6
RedhatEnterprise Linux Eus Version7.7
SuseLinux Enterprise Debuginfo Version11 Updatesp3
SuseLinux Enterprise Debuginfo Version11 Updatesp4
OpensuseOpensuse Version13.1
OpensuseOpensuse Version13.2
SuseLinux Enterprise Desktop Version11 Updatesp3
SuseLinux Enterprise Desktop Version11 Updatesp4
SuseLinux Enterprise Desktop Version12 Update-
SuseLinux Enterprise Server Version10 Updatesp4 SwEditionltss
SuseLinux Enterprise Server Version11 Updatesp1 SwEditionltss
SuseLinux Enterprise Server Version11 Updatesp2 SwEditionltss
SuseLinux Enterprise Server Version11 Updatesp3 SwPlatformvmware
SuseLinux Enterprise Server Version12 Update-
SuseManager Version1.7
   SuseLinux Enterprise Server Version11 Updatesp2 SwPlatform-
CanonicalUbuntu Linux Version12.04 SwEditionesm
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version15.04
RedhatSatellite Version5.6
   RedhatEnterprise Linux Version5.0
   RedhatEnterprise Linux Version6.0
FujitsuSparc Enterprise M3000 Firmware Version >= xcp < xcp_1121
   FujitsuSparc Enterprise M3000 Version-
FujitsuSparc Enterprise M4000 Firmware Version >= xcp < xcp_1121
   FujitsuSparc Enterprise M4000 Version-
FujitsuSparc Enterprise M5000 Firmware Version >= xcp < xcp_1121
   FujitsuSparc Enterprise M5000 Version-
FujitsuSparc Enterprise M8000 Firmware Version >= xcp < xcp_1121
   FujitsuSparc Enterprise M8000 Version-
FujitsuSparc Enterprise M9000 Firmware Version >= xcp < xcp_1121
   FujitsuSparc Enterprise M9000 Version-
HuaweiE6000 Firmware Version-
   HuaweiE6000 Version-
HuaweiE9000 Firmware Version-
   HuaweiE9000 Version-
HuaweiOceanstor 18500 Firmware Version-
   HuaweiOceanstor 18500 Version-
HuaweiOceanstor 18800 Firmware Version-
   HuaweiOceanstor 18800 Version-
HuaweiOceanstor 18800f Firmware Version-
   HuaweiOceanstor 18800f Version-
HuaweiOceanstor 9000 Firmware Version-
   HuaweiOceanstor 9000 Version-
HuaweiOceanstor Cse Firmware Version-
   HuaweiOceanstor Cse Version-
HuaweiOceanstor Hvs85t Firmware Version-
   HuaweiOceanstor Hvs85t Version-
HuaweiOceanstor S2600t Firmware Version-
   HuaweiOceanstor S2600t Version-
HuaweiOceanstor S5500t Firmware Version-
   HuaweiOceanstor S5500t Version-
HuaweiOceanstor S5600t Firmware Version-
   HuaweiOceanstor S5600t Version-
HuaweiOceanstor S5800t Firmware Version-
   HuaweiOceanstor S5800t Version-
HuaweiOceanstor S6800t Firmware Version-
   HuaweiOceanstor S6800t Version-
HuaweiQuidway S9300 Firmware Version-
   HuaweiQuidway S9300 Version-
HuaweiS7700 Firmware Version-
   HuaweiS7700 Version-
HuaweiS7700 Firmware Version-
   HuaweiS7700 Version-
Huawei9700 Firmware Version-
   Huawei9700 Version-
Huawei9700 Firmware Version-
   Huawei9700 Version-
HuaweiS12700 Firmware Version-
   HuaweiS12700 Version-
HuaweiS12700 Firmware Version-
   HuaweiS12700 Version-
HuaweiS2700 Firmware Version-
   HuaweiS2700 Version-
HuaweiS3700 Firmware Version-
   HuaweiS3700 Version-
HuaweiS5700ei Firmware Version-
   HuaweiS5700ei Version-
HuaweiS5700hi Firmware Version-
   HuaweiS5700hi Version-
HuaweiS5700si Firmware Version-
   HuaweiS5700si Version-
HuaweiS5710ei Firmware Version-
   HuaweiS5710ei Version-
HuaweiS5710hi Firmware Version-
   HuaweiS5710hi Version-
HuaweiS6700 Firmware Version-
   HuaweiS6700 Version-
HuaweiS2750 Firmware Version-
   HuaweiS2750 Version-
HuaweiS5700li Firmware Version-
   HuaweiS5700li Version-
HuaweiS5700s-li Firmware Version-
   HuaweiS5700s-li Version-
HuaweiS5720hi Firmware Version-
   HuaweiS5720hi Version-
HuaweiS2750 Firmware Version-
   HuaweiS2750 Version-
HuaweiS5700li Firmware Version-
   HuaweiS5700li Version-
HuaweiS5700s-li Firmware Version-
   HuaweiS5700s-li Version-
HuaweiS5720hi Firmware Version-
   HuaweiS5720hi Version-
HuaweiS5720ei Firmware Version-
   HuaweiS5720ei Version-
HuaweiTe60 Firmware Version-
   HuaweiTe60 Version-
HuaweiOceanstor Replicationdirector Versionv100r003c00
HuaweiPolicy Center Versionv100r003c00
HuaweiPolicy Center Versionv100r003c10
HuaweiSmc2.0 Versionv100r002c01
HuaweiSmc2.0 Versionv100r002c02
HuaweiSmc2.0 Versionv100r002c03
HuaweiSmc2.0 Versionv100r002c04
HuaweiUltravr Versionv100r003c00
IbmCognos Metrics Manager Version10.1
IbmCognos Metrics Manager Version10.1.1
IbmCognos Metrics Manager Version10.2
IbmCognos Metrics Manager Version10.2.1
IbmCognos Metrics Manager Version10.2.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 52.59% 0.979
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-327 Use of a Broken or Risky Cryptographic Algorithm

The product uses a broken or risky cryptographic algorithm or protocol.

https://kb.juniper.net/JSA10783
Third Party Advisory
http://marc.info/?l=bugtraq&m=144493176821532&w=2
Third Party Advisory
Issue Tracking
http://marc.info/?l=bugtraq&m=144043644216842&w=2
Third Party Advisory
Issue Tracking
http://www.securityfocus.com/bid/91787
Third Party Advisory
VDB Entry
http://marc.info/?l=bugtraq&m=143456209711959&w=2
Third Party Advisory
Issue Tracking
http://marc.info/?l=bugtraq&m=143629696317098&w=2
Third Party Advisory
Issue Tracking
http://marc.info/?l=bugtraq&m=143741441012338&w=2
Third Party Advisory
Issue Tracking
http://marc.info/?l=bugtraq&m=143817021313142&w=2
Third Party Advisory
Issue Tracking
http://marc.info/?l=bugtraq&m=143817899717054&w=2
Third Party Advisory
Issue Tracking
http://marc.info/?l=bugtraq&m=143818140118771&w=2
Third Party Advisory
Issue Tracking
http://marc.info/?l=bugtraq&m=144059660127919&w=2
Third Party Advisory
Issue Tracking
http://marc.info/?l=bugtraq&m=144059703728085&w=2
Third Party Advisory
Issue Tracking
http://marc.info/?l=bugtraq&m=144060576831314&w=2
Third Party Advisory
Issue Tracking
http://marc.info/?l=bugtraq&m=144060606031437&w=2
Third Party Advisory
Issue Tracking
http://marc.info/?l=bugtraq&m=144069189622016&w=2
Third Party Advisory
Issue Tracking
http://marc.info/?l=bugtraq&m=144102017024820&w=2
Third Party Advisory
Issue Tracking
http://marc.info/?l=bugtraq&m=144104533800819&w=2
Third Party Advisory
Issue Tracking
http://marc.info/?l=bugtraq&m=144104565600964&w=2
Third Party Advisory
Issue Tracking
http://www.securityfocus.com/bid/73684
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032599
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032600
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032707
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032708
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032734
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032788
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032858
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032868
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032910
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032990
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033071
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033072
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033386
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033415
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033431
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033432
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033737
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033769
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1036222
Third Party Advisory
VDB Entry