CVE-2016-1777
published 2016-03-24CVE-2016-1777: Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection mechanisms…
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
2.00%
78.4th percentile
Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | mac_os_x_server | <= 5.0.15 | — |
| apple | macos_mojave | — | — |
| apple | macos_sierra_10.12.2_security_update_2016-003_el_capitan_and_security_update_201 | — | — |
| apple | os_x_server | — | — |
| apple | tvos | — | — |
| apple | watchos_5 | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2016-1777: macOS Mojave 10.14
vendor_apple·2018-09-24·CVSS 7.5
CVE-2016-1777 [HIGH] CVE-2016-1777: macOS Mojave 10.14
Apple Security Update: About the security content of macOS Mojave 10.14
Product: macOS Mojave
Version: 10.14
CVE: CVE-2016-1777
Component: Security
Impact: An attacker may be able to exploit weaknesses in the RC4 cryptographic algorithm
Description: This issue was addressed by removing RC4.
Apple
CVE-2016-1777: iOS 12
vendor_apple·2018-09-17·CVSS 7.5
CVE-2016-1777 [HIGH] CVE-2016-1777: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2016-1777
Component: Security
Impact: An attacker may be able to exploit weaknesses in the RC4 cryptographic algorithm
Description: This issue was addressed by removing RC4.
Apple
CVE-2016-1777: watchOS 5
vendor_apple·2018-09-17·CVSS 7.5
CVE-2016-1777 [HIGH] CVE-2016-1777: watchOS 5
Apple Security Update: About the security content of watchOS 5
Product: watchOS 5
CVE: CVE-2016-1777
Component: Security
Impact: An attacker may be able to exploit weaknesses in the RC4 cryptographic algorithm
Description: This issue was addressed by removing RC4.
Apple
CVE-2016-1777: tvOS 12
vendor_apple·2018-09-17·CVSS 7.5
CVE-2016-1777 [HIGH] CVE-2016-1777: tvOS 12
Apple Security Update: About the security content of tvOS 12
Product: tvOS
Version: 12
CVE: CVE-2016-1777
Component: Security
Impact: An attacker may be able to exploit weaknesses in the RC4 cryptographic algorithm
Description: This issue was addressed by removing RC4.
Apple
CVE-2016-1777: macOS Sierra 10.12.2, Security Update 2016-003 El Capitan, and Security Update 2016-007 Yosemite
vendor_apple·2016-12-13·CVSS 7.5
CVE-2016-1777 [HIGH] CVE-2016-1777: macOS Sierra 10.12.2, Security Update 2016-003 El Capitan, and Security Update 2016-007 Yosemite
Apple Security Update: About the security content of macOS Sierra 10.12.2, Security Update 2016-003 El Capitan, and Security Update 2016-007 Yosemite
Product: macOS Sierra 10.12.2, Security Update 2016-003 El Capitan, and Security Update 2016-007 Yosemite
CVE: CVE-2016-1777
Component: OpenLDAP
Impact: An attacker may be able to exploit weaknesses in the RC4 cryptographic algorithm
Description: RC4 was removed as a default cipher.
Apple
CVE-2016-1777: OS X Server 5.1
vendor_apple·CVSS 7.5
CVE-2016-1777 [HIGH] CVE-2016-1777: OS X Server 5.1
Apple Security Update: About the security content of OS X Server 5.1
Product: OS X Server
Version: 5.1
CVE: CVE-2016-1777
Component: CVE-ID
GHSA
GHSA-xcwp-4r9f-392x: Web Server in Apple OS X Server before 5
ghsa_unreviewed·2022-05-17
CVE-2016-1777 [HIGH] GHSA-xcwp-4r9f-392x: Web Server in Apple OS X Server before 5
Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2016/Mar/msg00006.htmlhttp://www.securityfocus.com/bid/85054http://www.securitytracker.com/id/1035342https://support.apple.com/HT206173http://lists.apple.com/archives/security-announce/2016/Mar/msg00006.htmlhttp://www.securityfocus.com/bid/85054http://www.securitytracker.com/id/1035342https://support.apple.com/HT206173
2016-03-24
Published