CVE-2015-4953
published 2018-03-29CVE-2015-4953: IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for man-in-the-middle attackers to decrypt traffic by leveraging a…
PriorityP421medium4.8CVSS 3.0
AVNACHPRNUINSUCLILAN
EPSS
0.33%
24.6th percentile
IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for man-in-the-middle attackers to decrypt traffic by leveraging a weakness in its encryption protocol. IBM X-Force ID: 105197.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | bigfix_remote_control | — | — |
CVSS provenance
nvdv3.04.8MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6q4x-jxmf-pjpx: IBM BigFix Remote Control before Interim Fix pack 9
ghsa_unreviewed·2022-05-14
CVE-2015-4953 [MEDIUM] CWE-326 GHSA-6q4x-jxmf-pjpx: IBM BigFix Remote Control before Interim Fix pack 9
IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for man-in-the-middle attackers to decrypt traffic by leveraging a weakness in its encryption protocol. IBM X-Force ID: 105197.
Red Hat
ntp: bad authentication demobilizes ephemeral associations
vendor_redhat·2016-06-02·CVSS 7.5
CVE-2016-4953 [HIGH] ntp: bad authentication demobilizes ephemeral associations
ntp: bad authentication demobilizes ephemeral associations
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.
Statement: This issue did not affect the versions of ntp as shipped with any Red Hat Enterprise Linux version as they already included a fix for this issue in the patch provided to fix the CVE-2015-7979 issue. The fix for this issue (developed by Red Hat) was different from the one provided by upstream, and thus ntp versions in RHEL are not affected by CVE-2016-4953.
Package: ntp (Red Hat Enterprise Linux 5) - Not affected
Package: ntp (Red Hat Enterprise Linux 6) - Not affected
Package: ntp (Red Hat Enterprise Lin
No detection rules found.
No public exploits indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg1IV81388https://exchange.xforce.ibmcloud.com/vulnerabilities/105197https://www-304.ibm.com/support/docview.wss?uid=swg21972041http://www-01.ibm.com/support/docview.wss?uid=swg1IV81388https://exchange.xforce.ibmcloud.com/vulnerabilities/105197https://www-304.ibm.com/support/docview.wss?uid=swg21972041
2018-03-29
Published