MEDIUM · 5.9

CVE-2013-2566

The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis ...

Vulnerability Description

The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.

CVSS Score

5.9

MEDIUM

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
OracleCommunications Application Session Controller>= 3.0.0, <= 3.9.1
OracleHttp Server11.1.1.7.0
OracleIntegrated Lights Out Manager Firmware>= 3.0.0, <= 3.2.11
FujitsuSparc Enterprise M3000 Firmware>= xcp, < xcp_1121
FujitsuSparc Enterprise M3000-
FujitsuSparc Enterprise M4000 Firmware>= xcp, < xcp_1121
FujitsuSparc Enterprise M4000-
FujitsuSparc Enterprise M5000 Firmware>= xcp, < xcp_1121
FujitsuSparc Enterprise M5000-
FujitsuSparc Enterprise M8000 Firmware>= xcp, < xcp_1121
FujitsuSparc Enterprise M8000-
FujitsuSparc Enterprise M9000 Firmware>= xcp, < xcp_1121
FujitsuSparc Enterprise M9000-
FujitsuM10-1 Firmware>= xcp, < xcp2280
FujitsuM10-1-
FujitsuM10-4 Firmware>= xcp, < xcp2280
FujitsuM10-4-
FujitsuM10-4S Firmware>= xcp, < xcp2280
FujitsuM10-4S-
CanonicalUbuntu Linux12.04

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-2566?

CVE-2013-2566 is a vulnerability with a CVSS score of 5.9 (MEDIUM). The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis ...

How severe is CVE-2013-2566?

CVE-2013-2566 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-2566?

Check the references section above for vendor advisories and patch information. Affected products include: Oracle Communications Application Session Controller, Oracle Http Server, Oracle Integrated Lights Out Manager Firmware, Fujitsu Sparc Enterprise M3000 Firmware, Fujitsu Sparc Enterprise M3000.