CVE-2013-3587

Severity
5.9MEDIUM
EPSS
28.1%
top 3.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 21
Latest updateMay 5

Description

The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, aka a "BREACH" attack, a different issue than CVE-2012-4929.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages15 packages

CVEListV5https_protocolall
NVDf5/big-ip_protocol_security_module9.4.59.4.8+2
NVDf5/arx5.0.05.3.1+1
NVDf5/firepass6.0.06.1.0+1

🔴Vulnerability Details

2
GHSA
GHSA-hh3m-fgxm-fq25: The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted da2022-05-05
CVEList
CVE-2013-3587: The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted da2020-02-21

📋Vendor Advisories

1
Red Hat
BREACH attack against HTTP compression2013-08-02

💬Community

3
HackerOne
SSL BREACH attack (CVE-2013-3587)2017-07-30
HackerOne
Big Bug in SSL : breach compression attack (CVE-2013-3587) affect imgur.com2016-01-21
Bugzilla
CVE-2013-3587 BREACH attack against HTTP compression2013-08-08
CVE-2013-3587 (MEDIUM CVSS 5.9) | The HTTPS protocol | cvebase.io