cbcvebase.
CVE-2015-2808
published 2015-04-01

CVE-2015-2808: The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which…

low3.7CVSS 3.1
AVNACHPRNUINSUCLINAN
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.

Affected

71 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianopenjdk-8< openjdk-8 8u66-b01-1 (sid)openjdk-8 8u66-b01-1 (sid)
fujitsusparc_enterprise_m3000_firmware>= xcp < xcp_1121xcp_1121
fujitsusparc_enterprise_m4000_firmware>= xcp < xcp_1121xcp_1121
fujitsusparc_enterprise_m5000_firmware>= xcp < xcp_1121xcp_1121
fujitsusparc_enterprise_m8000_firmware>= xcp < xcp_1121xcp_1121
fujitsusparc_enterprise_m9000_firmware>= xcp < xcp_1121xcp_1121
huaweioceanstor_replicationdirector
huaweipolicy_center
huaweipolicy_center
huaweismc2.0
huaweismc2.0
huaweismc2.0
huaweismc2.0
huaweiultravr
ibmcognos_metrics_manager
ibmcognos_metrics_manager
ibmcognos_metrics_manager
ibmcognos_metrics_manager
ibmcognos_metrics_manager
opensuseopensuse

CVSS provenance

nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
osv9.8CRITICAL