CVE-2013-2566
published 2013-03-15CVE-2013-2566: The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct…
PriorityP259medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EXPLOIT
EPSS
84.42%
99.7th percentile
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| fujitsu | m10-1_firmware | >= xcp < xcp2280 | xcp2280 |
| fujitsu | m10-4_firmware | >= xcp < xcp2280 | xcp2280 |
| fujitsu | m10-4s_firmware | >= xcp < xcp2280 | xcp2280 |
| fujitsu | sparc_enterprise_m3000_firmware | >= xcp < xcp_1121 | xcp_1121 |
| fujitsu | sparc_enterprise_m4000_firmware | >= xcp < xcp_1121 | xcp_1121 |
| fujitsu | sparc_enterprise_m5000_firmware | >= xcp < xcp_1121 | xcp_1121 |
| fujitsu | sparc_enterprise_m8000_firmware | >= xcp < xcp_1121 | xcp_1121 |
| fujitsu | sparc_enterprise_m9000_firmware | >= xcp < xcp_1121 | xcp_1121 |
| mozilla | firefox | < 17.0.11 | 17.0.11 |
| mozilla | firefox | < 25.0.1 | 25.0.1 |
| mozilla | firefox | >= 24.1.0 < 24.1.1 | 24.1.1 |
| mozilla | seamonkey | < 2.22.1 | 2.22.1 |
| mozilla | thunderbird | < 24.1.1 | 24.1.1 |
| mozilla | thunderbird_esr | < 17.0.11 | 17.0.11 |
| oracle | communications_application_session_controller | 3.0.0 – 3.9.1 | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | integrated_lights_out_manager_firmware | 3.0.0 – 3.2.11 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect use of RC4 cipher suites in TLS/SSL traffic — the core indicator of CVE-2013-2566 exposure. Monitor TLS handshakes where RC4-based cipher suites are negotiated. ↗
- →Alert on large numbers of TLS/SSL sessions using the same plaintext — a behavioral pattern indicative of an active RC4 plaintext-recovery statistical analysis attack. ↗
- →Flag any TLS negotiation that selects RC4 stream cipher suites, particularly in contexts where SSL 3.0 or TLS is in use, as this is the vulnerable algorithm path for CVE-2013-2566. ↗
- ·CVE-2013-2566 is a design flaw in the RC4 algorithm itself, not an implementation bug — no code patch exists; mitigation requires disabling RC4 cipher suites entirely. ↗
- ·Red Hat explicitly will not fix this in RHEL 5 or 6 for gnutls, nss, or openssl packages — environments running these must rely on configuration-level RC4 disablement. ↗
- ·Mitsubishi Electric ICS devices (air conditioning systems) are confirmed affected by CVE-2013-2566; exploitation requires high attack complexity and network sniffing capability. ↗
- ·No known public exploits specifically target CVE-2013-2566 in the Mitsubishi Electric ICS context; the vulnerability has high attack complexity. ↗
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_ubuntu7.5HIGH
vendor_redhat5.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f67x-vqh9-8p43: The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct pl
ghsa_unreviewed·2022-05-13
CVE-2013-2566 [MEDIUM] CWE-326 GHSA-f67x-vqh9-8p43: The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct pl
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.
CISA ICS
Mitsubishi Electric Air Conditioning Systems
cisa_ics·2022-06-20
Mitsubishi Electric Air Conditioning Systems
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Mitsubishi Electric Air Conditioning Systems
Last RevisedJune 20, 2022
Alert CodeICSA-22-160-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely
- Vendor: Mitsubishi Electric
- Equipment: Air Conditioning Systems
- Vulnerabilities: Use of a Broken or Risky Cryptographic Algorithm, Exposure of Sensitive Information to an Unauthorized Actor, Channel Accessible by Non-Endpoint
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to disclose or tamper data in communication between the air conditioning system and
CISA ICS
GE UR family
cisa_ics·2021-03-16
GE UR family
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
GE UR family
Last RevisedMarch 16, 2021
Alert CodeICSA-21-075-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: GE
- Equipment: UR Family
- Vulnerabilities: Inadequate Encryption Strength, Session Fixation, Exposure of Sensitive Information to an Unauthorized Actor, Improper Input Validation, Unrestricted Upload of File with Dangerous Type, Insecure Default Variable Initialization, Use of Hard-coded Credentials
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to acce
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2013-11-21·CVSS 7.5
CVE-2013-1741 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into connecting to a malicious server, an attacker could possibly
exploit these to cause a denial of service via application crash,
potentially execute arbitrary code, or lead to information disclosure.
(CVE-2013-1741, CVE-2013-2566, CVE-2013-5605, CVE-2013-5607)
Instructions: After a standard system update you need to restart Thunderbird to make
all the necessary changes.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-11-20·CVSS 7.5
CVE-2013-1741 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Multiple security issues were discovered in Firefox. If a user were tricked
into opening a specially crafted page, an attacker could possibly exploit
these to cause a denial of service via application crash, potentially
execute arbitrary code, or lead to information disclosure. (CVE-2013-1741,
CVE-2013-2566, CVE-2013-5605, CVE-2013-5607)
Instructions: After a standard system update you need to restart Firefox to make
all the necessary changes.
Red Hat
SSL/TLS: Attack against RC4 stream cipher
vendor_redhat·2013-03-15·CVSS 5.9
CVE-2013-2566 [MEDIUM] SSL/TLS: Attack against RC4 stream cipher
SSL/TLS: Attack against RC4 stream cipher
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.
Statement: This flaw is related to the design of the RC4 protocol and not its implementation. More details and a possible work around is mentioned in https://bugzilla.redhat.com/show_bug.cgi?id=921947#c8. Therefore there are no plans to correct this issue in Red Hat Enterprise Linux 5 and 6.
Package: gnutls (Red Hat Enterprise Linux 5) - Will not fix
Package: nss (Red Hat Enterprise Linux 5) - Will not fix
Package: openssl (Red Hat Enterprise Linux 5) - Will not fix
Package:
No detection rules found.
Bugzilla
CVE-2014-3566 SSL/TLS: Padding Oracle On Downgraded Legacy Encryption attack
bugzilla·2014-10-15·CVSS 3.4
CVE-2014-3566 [LOW] CVE-2014-3566 SSL/TLS: Padding Oracle On Downgraded Legacy Encryption attack
CVE-2014-3566 SSL/TLS: Padding Oracle On Downgraded Legacy Encryption attack
Bodo Möller, Thai Duong and Krzysztof Kotowicz of Google discovered a flaw in the design of SSL version 3.0 that would allow an attacker to calculate the plaintext of secure connections, allowing, for example, secure HTTP cookies to be stolen.
References:
http://googleonlinesecurity.blogspot.com/2014/10/this-poodle-bites-exploiting-ssl-30.html
https://www.openssl.org/~bodo/ssl-poodle.pdf
Discussion:
Knowledgebase article:
https://access.redhat.com/articles/1232123
To mitigate this vulnerability, it is recommended that you explicitly disable SSLv3.0 in all affected packages. Additional instructions to do this for each affected package, as well as updates that disable SSLv3.0 by default, are being developed by
Bugzilla
CVE-2013-2566 SSL/TLS: Attack against RC4 stream cipher
bugzilla·2013-03-15·CVSS 5.9
CVE-2013-2566 [MEDIUM] CVE-2013-2566 SSL/TLS: Attack against RC4 stream cipher
CVE-2013-2566 SSL/TLS: Attack against RC4 stream cipher
A new attack was discovered against TLS that allows an attacker to recover a limited amount of plaintext from a TLS connection when RC4 encryption is used. The attacks arise from statistical flaws in the keystream generated by the RC4 algorithm which become apparent in TLS ciphertexts when the same plaintext is repeatedly encrypted at a fixed location across many TLS sessions.
Reference:
http://www.isg.rhul.ac.uk/tls/
http://blog.cryptographyengineering.com/2013/03/attack-of-week-rc4-is-kind-of-broken-in.html
Discussion:
CVE-2013-2566:
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has
many single-byte biases, which makes it easier for remote attackers to
conduct plaintext-recovery attacks via statistical analy
Bugzilla
Deal with "On the Security of RC4 in TLS" plaintext recovery attack
bugzilla·2013-03-12
[MEDIUM] Deal with "On the Security of RC4 in TLS" plaintext recovery attack
Deal with "On the Security of RC4 in TLS" plaintext recovery attack
Created attachment 724189
"On the Security of RC4 in TLS"
I got permission from the authors to share this paper with security-group. The work has also been publicly disclosed:
https://news.ycombinator.com/item?id=5364807
http://blog.cryptographyengineering.com/2013/03/attack-of-week-rc4-is-kind-of-broken-in.html
----- Forwarded Message -----
From: "Kenny Paterson"
To: "Brian Smith"
Cc: "D. J. Bernstein" , "Jacob Schuldt" , "Bertram Poettering" , "Nadhem Alfardan (2009)" , [email protected], "Kenny Paterson"
Sent: Tuesday, March 12, 2013 4:03:15 PM
Subject: Re: Security of RC4 in TLS
Hi Brian,
Thanks for getting back to us and for the positive feedback on the paper. Given very recent events, I think you may as well shar
arXiv
Oblivious DNS over HTTPS (ODoH): A Practical Privacy Enhancement to DNS
arxiv_fulltext·2020-11-19
Oblivious DNS over HTTPS (ODoH): A Practical Privacy Enhancement to DNS
Oblivious DNS over HTTPS (ODoH): A Practical Privacy Enhancement to DNS
Sudheesh Singanamalla ^ *, Suphanat Chunhapanya ^*, Marek Vavruša ^*, Tanya Verma ^*, Peter Wu ^*
Marwan Fayed ^*, Kurtis Heimerl ^ , Nick Sullivan ^*, Christopher Wood ^*
^* Cloudflare Inc., ^ University of Washington
## Abstract
The Domain Name System (DNS) is the foundation of a human-usable Internet, responding to client queries for hostnames with corresponding IP addresses and records. Traditional DNS is also unencrypted, and leaks user information to network operators.
Recent efforts to secure DNS using DNS over TLS (DoT) and DNS over HTTPS (DoH) have been gaining traction, ostensibly protecting traffic and hiding content from on-lookers. However, one of the criticisms of DoT and DoH is brought to bear by th
arXiv
Secure by default - the case of TLS
arxiv_fulltext·2017-08-24
Secure by default - the case of TLS
Secure by default -- the case of TLS
Martin Stanek \ 1ex]
Department of Computer Science
Comenius University
@dcs.fmph.uniba.sk
## Abstract
Default configuration of various software applications often neglects security objectives.
We tested the default configuration of TLS in dozen web and application servers.
The results show that ``secure by default'' principle should be adopted more broadly
by developers and package maintainers. In addition, system administrators cannot
rely blindly on default security options.
: TLS, secure defaults, testing.
## Introduction
Security often depends on prudent configuration of software components used in a deployed
system. All necessary security controls and options are there, but one have
to turn them on or simply start using them. Unfortunately
http://blog.cryptographyengineering.com/2013/03/attack-of-week-rc4-is-kind-of-broken-in.htmlhttp://cr.yp.to/talks/2013.03.12/slides.pdfhttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://marc.info/?l=bugtraq&m=143039468003789&w=2http://my.opera.com/securitygroup/blog/2013/03/20/on-the-precariousness-of-rc4http://security.gentoo.org/glsa/glsa-201406-19.xmlhttp://www.isg.rhul.ac.uk/tls/http://www.mozilla.org/security/announce/2013/mfsa2013-103.htmlhttp://www.opera.com/docs/changelogs/unified/1215/http://www.opera.com/security/advisory/1046http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/58796http://www.ubuntu.com/usn/USN-2031-1http://www.ubuntu.com/usn/USN-2032-1https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888https://security.gentoo.org/glsa/201504-01http://blog.cryptographyengineering.com/2013/03/attack-of-week-rc4-is-kind-of-broken-in.htmlhttp://cr.yp.to/talks/2013.03.12/slides.pdfhttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://marc.info/?l=bugtraq&m=143039468003789&w=2http://my.opera.com/securitygroup/blog/2013/03/20/on-the-precariousness-of-rc4http://security.gentoo.org/glsa/glsa-201406-19.xmlhttp://www.isg.rhul.ac.uk/tls/http://www.mozilla.org/security/announce/2013/mfsa2013-103.htmlhttp://www.opera.com/docs/changelogs/unified/1215/http://www.opera.com/security/advisory/1046http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/58796http://www.ubuntu.com/usn/USN-2031-1http://www.ubuntu.com/usn/USN-2032-1https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888https://security.gentoo.org/glsa/201504-01
2013-03-15
Published