5.9
CVE-2017-15533
- EPSS 0.28%
- Veröffentlicht 17.05.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:44
- Quelle secure@symantec.com
- CVE-Watchlists
- Unerledigt
Symantec SSL Visibility (SSLV) 3.8.4FC, 3.10 prior to 3.10.4.1, 3.11, and 3.12 prior to 3.12.2.1 are vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. All affected SSLV versions act as weak oracles according the oracle classification used in the ROBOT research paper. A remote attacker, who has captured a pre-recorded SSL session inspected by SSLV, can establish multiple millions of crafted SSL connections to the target and obtain the session keys required to decrypt the pre-recorded SSL session.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Broadcom ≫ Ssl Visibility Appliance Version3.8.4fc
Broadcom ≫ Ssl Visibility Appliance Version3.10
Broadcom ≫ Ssl Visibility Appliance Version3.11
Broadcom ≫ Ssl Visibility Appliance Version3.12
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.514 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-203 Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.