CVE-2015-2808 : Détail

CVE-2015-2808

A02-Cryptographic Failures
0.44%V3
Network
2015-03-31
22h00 +00:00
2023-09-07
14h46 +00:00
Notifications pour un CVE
Restez informé de toutes modifications pour un CVE spécifique.
Gestion des notifications

Descriptions du CVE

The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.

Informations du CVE

Faiblesses connexes

CWE-ID Nom de la faiblesse Source
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.

Métriques

Métriques Score Gravité CVSS Vecteur Source
V2 5 AV:N/AC:L/Au:N/C:P/I:N/A:N [email protected]

EPSS

EPSS est un modèle de notation qui prédit la probabilité qu'une vulnérabilité soit exploitée.

Score EPSS

Le modèle EPSS produit un score de probabilité compris entre 0 et 1 (0 et 100 %). Plus la note est élevée, plus la probabilité qu'une vulnérabilité soit exploitée est grande.

Percentile EPSS

Le percentile est utilisé pour classer les CVE en fonction de leur score EPSS. Par exemple, une CVE dans le 95e percentile selon son score EPSS est plus susceptible d'être exploitée que 95 % des autres CVE. Ainsi, le percentile sert à comparer le score EPSS d'une CVE par rapport à d'autres CVE.

Products Mentioned

Configuraton 0

Oracle>>Communications_application_session_controller >> Version From (including) 3.0.0 To (including) 3.9.0

Oracle>>Communications_policy_management >> Version To (excluding) 9.9.2

Oracle>>Http_server >> Version 11.1.1.7.0

Oracle>>Http_server >> Version 11.1.1.9.0

Oracle>>Http_server >> Version 12.1.3.0.0

Oracle>>Http_server >> Version 12.2.1.1.0

Oracle>>Http_server >> Version 12.2.1.2.0

Oracle>>Integrated_lights_out_manager_firmware >> Version From (including) 3.0.0 To (including) 3.2.11

Oracle>>Integrated_lights_out_manager_firmware >> Version From (including) 4.0.0 To (including) 4.0.4

Configuraton 0

Debian>>Debian_linux >> Version 7.0

Debian>>Debian_linux >> Version 8.0

Configuraton 0

Redhat>>Satellite >> Version 5.7

Redhat>>Enterprise_linux_desktop >> Version 5.0

Redhat>>Enterprise_linux_desktop >> Version 6.0

Redhat>>Enterprise_linux_desktop >> Version 7.0

Redhat>>Enterprise_linux_eus >> Version 6.6

Redhat>>Enterprise_linux_eus >> Version 7.1

Redhat>>Enterprise_linux_eus >> Version 7.2

Redhat>>Enterprise_linux_eus >> Version 7.3

Redhat>>Enterprise_linux_eus >> Version 7.4

Redhat>>Enterprise_linux_eus >> Version 7.5

Redhat>>Enterprise_linux_eus >> Version 7.6

Redhat>>Enterprise_linux_eus >> Version 7.7

Redhat>>Enterprise_linux_server >> Version 5.0

Redhat>>Enterprise_linux_server >> Version 6.0

Redhat>>Enterprise_linux_server >> Version 7.0

Redhat>>Enterprise_linux_server_aus >> Version 6.6

Redhat>>Enterprise_linux_server_aus >> Version 7.3

Redhat>>Enterprise_linux_server_aus >> Version 7.4

Redhat>>Enterprise_linux_server_aus >> Version 7.6

Redhat>>Enterprise_linux_server_aus >> Version 7.7

Redhat>>Enterprise_linux_server_tus >> Version 7.3

Redhat>>Enterprise_linux_server_tus >> Version 7.6

Redhat>>Enterprise_linux_server_tus >> Version 7.7

Redhat>>Enterprise_linux_workstation >> Version 5.0

Redhat>>Enterprise_linux_workstation >> Version 6.0

Redhat>>Enterprise_linux_workstation >> Version 7.0

Configuraton 0

Suse>>Linux_enterprise_debuginfo >> Version 11

Suse>>Linux_enterprise_debuginfo >> Version 11

Opensuse>>Opensuse >> Version 13.1

Opensuse>>Opensuse >> Version 13.2

Suse>>Linux_enterprise_desktop >> Version 11

Suse>>Linux_enterprise_desktop >> Version 11

Suse>>Linux_enterprise_desktop >> Version 12

Suse>>Linux_enterprise_server >> Version 10

Suse>>Linux_enterprise_server >> Version 11

Suse>>Linux_enterprise_server >> Version 11

Suse>>Linux_enterprise_server >> Version 11

Suse>>Linux_enterprise_server >> Version 12

Suse>>Linux_enterprise_software_development_kit >> Version 11

Suse>>Linux_enterprise_software_development_kit >> Version 12

Configuraton 0

Suse>>Manager >> Version 1.7

Suse>>Linux_enterprise_server >> Version 11

Configuraton 0

Canonical>>Ubuntu_linux >> Version 12.04

Canonical>>Ubuntu_linux >> Version 14.04

Canonical>>Ubuntu_linux >> Version 15.04

Configuraton 0

Redhat>>Satellite >> Version 5.6

Redhat>>Enterprise_linux >> Version 5.0

Redhat>>Enterprise_linux >> Version 6.0

Configuraton 0

Fujitsu>>Sparc_enterprise_m3000_firmware >> Version From (including) xcp To (excluding) xcp_1121

Fujitsu>>Sparc_enterprise_m3000 >> Version -

Configuraton 0

Fujitsu>>Sparc_enterprise_m4000_firmware >> Version From (including) xcp To (excluding) xcp_1121

Fujitsu>>Sparc_enterprise_m4000 >> Version -

Configuraton 0

Fujitsu>>Sparc_enterprise_m5000_firmware >> Version From (including) xcp To (excluding) xcp_1121

Fujitsu>>Sparc_enterprise_m5000 >> Version -

Configuraton 0

Fujitsu>>Sparc_enterprise_m8000_firmware >> Version From (including) xcp To (excluding) xcp_1121

Fujitsu>>Sparc_enterprise_m8000 >> Version -

Configuraton 0

Fujitsu>>Sparc_enterprise_m9000_firmware >> Version From (including) xcp To (excluding) xcp_1121

Fujitsu>>Sparc_enterprise_m9000 >> Version -

Configuraton 0

Huawei>>E6000_firmware >> Version -

Huawei>>E6000 >> Version -

Configuraton 0

Huawei>>E9000_firmware >> Version -

Huawei>>E9000 >> Version -

Configuraton 0

Huawei>>Oceanstor_18500_firmware >> Version -

Huawei>>Oceanstor_18500 >> Version -

Configuraton 0

Huawei>>Oceanstor_18800_firmware >> Version -

Huawei>>Oceanstor_18800 >> Version -

Configuraton 0

Huawei>>Oceanstor_18800f_firmware >> Version -

Huawei>>Oceanstor_18800f >> Version -

Configuraton 0

Huawei>>Oceanstor_9000_firmware >> Version -

Huawei>>Oceanstor_9000 >> Version -

Configuraton 0

Huawei>>Oceanstor_cse_firmware >> Version -

Huawei>>Oceanstor_cse >> Version -

Configuraton 0

Huawei>>Oceanstor_hvs85t_firmware >> Version -

Huawei>>Oceanstor_hvs85t >> Version -

Configuraton 0

Huawei>>Oceanstor_s2600t_firmware >> Version -

Huawei>>Oceanstor_s2600t >> Version -

Configuraton 0

Huawei>>Oceanstor_s5500t_firmware >> Version -

Huawei>>Oceanstor_s5500t >> Version -

Configuraton 0

Huawei>>Oceanstor_s5600t_firmware >> Version -

Huawei>>Oceanstor_s5600t >> Version -

Configuraton 0

Huawei>>Oceanstor_s5800t_firmware >> Version -

Huawei>>Oceanstor_s5800t >> Version -

Configuraton 0

Huawei>>Oceanstor_s6800t_firmware >> Version -

Huawei>>Oceanstor_s6800t >> Version -

Configuraton 0

Huawei>>Oceanstor_vis6600t_firmware >> Version -

Huawei>>Oceanstor_vis6600t >> Version -

Configuraton 0

Huawei>>Quidway_s9300_firmware >> Version -

Huawei>>Quidway_s9300 >> Version -

Configuraton 0

Huawei>>S7700_firmware >> Version -

Huawei>>S7700 >> Version -

Configuraton 0

Huawei>>S7700_firmware >> Version -

Huawei>>S7700 >> Version -

Configuraton 0

Huawei>>9700_firmware >> Version -

Huawei>>9700 >> Version -

Configuraton 0

Huawei>>9700_firmware >> Version -

Huawei>>9700 >> Version -

Configuraton 0

Huawei>>S12700_firmware >> Version -

Huawei>>S12700 >> Version -

Configuraton 0

Huawei>>S12700_firmware >> Version -

Huawei>>S12700 >> Version -

Configuraton 0

Huawei>>S2700_firmware >> Version -

Huawei>>S2700 >> Version -

Configuraton 0

Huawei>>S3700_firmware >> Version -

Huawei>>S3700 >> Version -

Configuraton 0

Huawei>>S5700ei_firmware >> Version -

Huawei>>S5700ei >> Version -

Configuraton 0

Huawei>>S5700hi_firmware >> Version -

Huawei>>S5700hi >> Version -

Configuraton 0

Huawei>>S5700si_firmware >> Version -

Huawei>>S5700si >> Version -

Configuraton 0

Huawei>>S5710ei_firmware >> Version -

Huawei>>S5710ei >> Version -

Configuraton 0

Huawei>>S5710hi_firmware >> Version -

Huawei>>S5710hi >> Version -

Configuraton 0

Huawei>>S6700_firmware >> Version -

Huawei>>S6700 >> Version -

Configuraton 0

Huawei>>S2750_firmware >> Version -

Huawei>>S2750 >> Version -

Configuraton 0

Huawei>>S5700li_firmware >> Version -

Huawei>>S5700li >> Version -

Configuraton 0

Huawei>>S5700s-li_firmware >> Version -

Huawei>>S5700s-li >> Version -

Configuraton 0

Huawei>>S5720hi_firmware >> Version -

Huawei>>S5720hi >> Version -

Configuraton 0

Huawei>>S2750_firmware >> Version -

Huawei>>S2750 >> Version -

Configuraton 0

Huawei>>S5700li_firmware >> Version -

Huawei>>S5700li >> Version -

Configuraton 0

Huawei>>S5700s-li_firmware >> Version -

Huawei>>S5700s-li >> Version -

Configuraton 0

Huawei>>S5720hi_firmware >> Version -

Huawei>>S5720hi >> Version -

Configuraton 0

Huawei>>S5720ei_firmware >> Version -

Huawei>>S5720ei >> Version -

Configuraton 0

Huawei>>Te60_firmware >> Version -

Huawei>>Te60 >> Version -

Configuraton 0

Huawei>>Oceanstor_replicationdirector >> Version v100r003c00

Huawei>>Policy_center >> Version v100r003c00

Huawei>>Policy_center >> Version v100r003c10

Huawei>>Smc2.0 >> Version v100r002c01

Huawei>>Smc2.0 >> Version v100r002c02

Huawei>>Smc2.0 >> Version v100r002c03

Huawei>>Smc2.0 >> Version v100r002c04

Huawei>>Ultravr >> Version v100r003c00

Configuraton 0

Ibm>>Cognos_metrics_manager >> Version 10.1

Ibm>>Cognos_metrics_manager >> Version 10.1.1

Ibm>>Cognos_metrics_manager >> Version 10.2

Ibm>>Cognos_metrics_manager >> Version 10.2.1

Ibm>>Cognos_metrics_manager >> Version 10.2.2

Références

https://kb.juniper.net/JSA10783
Tags : Third Party Advisory