8.1

CVE-2015-8960

Medienbericht
Exploit
The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which makes it easier for man-in-the-middle attackers to spoof TLS servers by leveraging knowledge of the secret key for an arbitrary installed client X.509 certificate, aka the "Key Compromise Impersonation (KCI)" issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ietf ≫ Transport Layer Security Version <= 1.2
   Apple ≫ Safari Version -
   Google ≫ Chrome Version -
   Microsoft ≫ Internet Explorer Version -
   Mozilla ≫ Firefox Version -
   Opera ≫ Opera Browser Version -
Netapp ≫ Data Ontap Edge Version -
Netapp ≫ Host Agent Version -
Netapp ≫ Oncommand Shift Version -
Netapp ≫ Smi-s Provider Version -
Netapp ≫ Snapdrive Version - SwPlatform unix
Netapp ≫ Snapdrive Version - SwPlatform windows
Netapp ≫ Snapmanager Version - SwPlatform oracle
Netapp ≫ Snapmanager Version - SwPlatform sap
Netapp ≫ Snapprotect Version -
Netapp ≫ System Setup Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.95% 0.776
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

http://twitter.com/matthew_d_green/statuses/630908726950674433
Third Party Advisory
Technical Description
Press/Media Coverage
http://www.openwall.com/lists/oss-security/2016/09/20/4
Third Party Advisory
Mailing List
Technical Description
http://www.securityfocus.com/bid/93071
Third Party Advisory
Broken Link
VDB Entry
https://kcitls.org
Exploit
Technical Description
https://security.netapp.com/advisory/ntap-20180626-0002/
Third Party Advisory
https://www.usenix.org/system/files/conference/woot15/woot15-paper-hlauschek.pdf
Exploit
Mitigation
Technical Description