cbcvebase.
CVE-2013-2566
published 2013-03-15

CVE-2013-2566: The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct…

PriorityP259medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EXPLOIT
EPSS
84.42%
99.7th percentile
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
fujitsum10-1_firmware>= xcp < xcp2280xcp2280
fujitsum10-4_firmware>= xcp < xcp2280xcp2280
fujitsum10-4s_firmware>= xcp < xcp2280xcp2280
fujitsusparc_enterprise_m3000_firmware>= xcp < xcp_1121xcp_1121
fujitsusparc_enterprise_m4000_firmware>= xcp < xcp_1121xcp_1121
fujitsusparc_enterprise_m5000_firmware>= xcp < xcp_1121xcp_1121
fujitsusparc_enterprise_m8000_firmware>= xcp < xcp_1121xcp_1121
fujitsusparc_enterprise_m9000_firmware>= xcp < xcp_1121xcp_1121
mozillafirefox< 17.0.1117.0.11
mozillafirefox< 25.0.125.0.1
mozillafirefox>= 24.1.0 < 24.1.124.1.1
mozillaseamonkey< 2.22.12.22.1
mozillathunderbird< 24.1.124.1.1
mozillathunderbird_esr< 17.0.1117.0.11
oraclecommunications_application_session_controller3.0.0 – 3.9.1
oraclehttp_server
oraclehttp_server
oraclehttp_server
oraclehttp_server
oraclehttp_server
oracleintegrated_lights_out_manager_firmware3.0.0 – 3.2.11

Detection & IOCsextracted from sources · hover to see the quote

  • Detect use of RC4 cipher suites in TLS/SSL traffic — the core indicator of CVE-2013-2566 exposure. Monitor TLS handshakes where RC4-based cipher suites are negotiated.
  • Alert on large numbers of TLS/SSL sessions using the same plaintext — a behavioral pattern indicative of an active RC4 plaintext-recovery statistical analysis attack.
  • Flag any TLS negotiation that selects RC4 stream cipher suites, particularly in contexts where SSL 3.0 or TLS is in use, as this is the vulnerable algorithm path for CVE-2013-2566.
  • ·CVE-2013-2566 is a design flaw in the RC4 algorithm itself, not an implementation bug — no code patch exists; mitigation requires disabling RC4 cipher suites entirely.
  • ·Red Hat explicitly will not fix this in RHEL 5 or 6 for gnutls, nss, or openssl packages — environments running these must rely on configuration-level RC4 disablement.
  • ·Mitsubishi Electric ICS devices (air conditioning systems) are confirmed affected by CVE-2013-2566; exploitation requires high attack complexity and network sniffing capability.
  • ·No known public exploits specifically target CVE-2013-2566 in the Mitsubishi Electric ICS context; the vulnerability has high attack complexity.

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_ubuntu7.5HIGH
vendor_redhat5.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.