CVE-2015-2808

Advisory lineage Upstream: 0 Downstream: 32
Modified
Published: 01 Apr 2015, 00:00
Last modified:28 May 2026, 12:53

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
23.82% HIGH
24% probability -11.49%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Apr 2015, 00:00
Published
Vulnerability first disclosed
28 May 2026, 12:53
Last Modified
Vulnerability information updated

Description

The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.

CVSS Metrics

  • v3.1LOWScore: 3.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 23.82% Percentile: 96%

Techniques & Countermeasures

  • CWE-327Use of a Broken or Risky Cryptographic Algorithm

    The product uses a broken or risky cryptographic algorithm or protocol.

Affected Systems

  • canonicalubuntu_linux

    12.04 | 14.04 | 15.04

  • debiandebian_linux

    7.0 | 8.0

  • fujitsusparc_enterprise_m3000_firmware

    ≥ xcp, < xcp_1121

  • fujitsusparc_enterprise_m4000_firmware

    ≥ xcp, < xcp_1121

  • fujitsusparc_enterprise_m5000_firmware

    ≥ xcp, < xcp_1121

  • fujitsusparc_enterprise_m8000_firmware

    ≥ xcp, < xcp_1121

  • fujitsusparc_enterprise_m9000_firmware

    ≥ xcp, < xcp_1121

  • huawei9700_firmware

    na

  • huaweie6000_firmware

    na

  • huaweie9000_firmware

    na

  • huaweioceanstor_18500_firmware

    na

  • huaweioceanstor_18800_firmware

    na

  • huaweioceanstor_18800f_firmware

    na

  • huaweioceanstor_9000_firmware

    na

  • huaweioceanstor_cse_firmware

    na

  • huaweioceanstor_hvs85t_firmware

    na

  • huaweioceanstor_replicationdirector

    v100r003c00

  • huaweioceanstor_s2600t_firmware

    na

  • huaweioceanstor_s5500t_firmware

    na

  • huaweioceanstor_s5600t_firmware

    na

  • huaweioceanstor_s5800t_firmware

    na

  • huaweioceanstor_s6800t_firmware

    na

  • huaweioceanstor_vis6600t_firmware

    na

  • huaweipolicy_center

    v100r003c00 | v100r003c10

  • huaweiquidway_s9300_firmware

    na

  • huaweis12700_firmware

    na

  • huaweis2700_firmware

    na

  • huaweis2750_firmware

    na

  • huaweis3700_firmware

    na

  • huaweis5700ei_firmware

    na

  • huaweis5700hi_firmware

    na

  • huaweis5700li_firmware

    na

  • huaweis5700s-li_firmware

    na

  • huaweis5700si_firmware

    na

  • huaweis5710ei_firmware

    na

  • huaweis5710hi_firmware

    na

  • huaweis5720ei_firmware

    na

  • huaweis5720hi_firmware

    na

  • huaweis6700_firmware

    na

  • huaweis7700_firmware

    na

  • huaweismc2.0

    v100r002c01 | v100r002c02 | v100r002c03 | v100r002c04

  • huaweite60_firmware

    na

  • huaweiultravr

    v100r003c00

  • ibmcognos_metrics_manager

    10.1 | 10.1.1 | 10.2 | 10.2.1 | 10.2.2

  • opensuseopensuse

    13.1 | 13.2

  • oraclecommunications_application_session_controller

    ≥ 3.0.0, ≤ 3.9.0

  • oraclecommunications_policy_management

    < 9.9.2

  • oraclehttp_server

    11.1.1.7.0 | 11.1.1.9.0 | 12.1.3.0.0 | 12.2.1.1.0 | 12.2.1.2.0

  • oracleintegrated_lights_out_manager_firmware

    ≥ 3.0.0, ≤ 3.2.11 | ≥ 4.0.0, ≤ 4.0.4

  • redhatenterprise_linux_desktop

    5.0 | 6.0 | 7.0

Showing first 50 affected entries in server-rendered view.

References (101)