CVE-2015-2808

⚪ Do wiadomości

Słabość algorytmu RC4 w protokołach TLS i SSL umożliwia ataki na dane płaskie.

CVSS
3.7
EPSS
23.4%
Exploit
none
Vendor
huawei
Opis źródłowy (NVD)

The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS3.7
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)23.4%
Opublikowano (NVD)2015-04-01 02:00:35 UTC
Ostatnia modyfikacja (NVD)2026-05-28 14:16:16 UTC
Referencje