« Volver al listado

CVE-2015-2077

Estado: ModificadaMedia (5)—

The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware AdBlocker (alpha) 1.3.69.1, Qustodio for Windows, Atom Security, Inc. StaffCop 5.8, and other products, uses the same X.509 certificate private key for a root CA certificate across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging knowledge of this key, as originally reported for Superfish VisualDiscovery on certain Lenovo Notebook laptop products.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-2077",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-02-24T23:59:00.063",
  "references": [
    {
      "url": "http://blog.erratasec.com/2015/02/extracting-superfish-certificate.html#.VOq6Yfn8Fp4",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://blog.erratasec.com/2015/02/some-notes-on-superfish.html#.VOq6Yvn8Fp4",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marcrogers.org/2015/02/19/lenovo-installs-adware-on-customer-laptops-and-compromises-all-ssl/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://news.lenovo.com/article_display.cfm?article_id=1929",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://support.lenovo.com/us/en/product_security/superfish",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/529496",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/72693",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id/1031779",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.theguardian.com/technology/2015/feb/19/lenovo-accused-compromising-user-security-installing-adware-pcs-superfish",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.us-cert.gov/cas/techalerts/TA15-051A.html",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.wired.com/2015/02/lenovo-superfish/",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://blog.filippo.io/komodia-superfish-ssl-validation-is-broken/",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.facebook.com/notes/protect-the-graph/windows-ssl-interception-gone-wild/1570074729899339",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://blog.erratasec.com/2015/02/extracting-superfish-certificate.html#.VOq6Yfn8Fp4",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://blog.erratasec.com/2015/02/some-notes-on-superfish.html#.VOq6Yvn8Fp4",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marcrogers.org/2015/02/19/lenovo-installs-adware-on-customer-laptops-and-compromises-all-ssl/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://news.lenovo.com/article_display.cfm?article_id=1929",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.lenovo.com/us/en/product_security/superfish",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/529496",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/72693",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1031779",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.theguardian.com/technology/2015/feb/19/lenovo-accused-compromising-user-security-installing-adware-pcs-superfish",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.us-cert.gov/cas/techalerts/TA15-051A.html",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.wired.com/2015/02/lenovo-superfish/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://blog.filippo.io/komodia-superfish-ssl-validation-is-broken/",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.facebook.com/notes/protect-the-graph/windows-ssl-interception-gone-wild/1570074729899339",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware AdBlocker (alpha) 1.3.69.1, Qustodio for Windows, Atom Security, Inc. StaffCop 5.8, and other products, uses the same X.509 certificate private key for a root CA certificate across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging knowledge of this key, as originally reported for Superfish VisualDiscovery on certain Lenovo Notebook laptop products."
    },
    {
      "lang": "es",
      "value": "El SDK para Komodia Redirector con el digestor de SSL, utilizado en Lavasoft Ad-Aware Web Companion 1.1.885.1766 y Ad-Aware AdBlocker (alpha) 1.3.69.1, Qustodio para Windows, Atom Security, Inc. StaffCop 5.8, y otros productos, utiliza la misma clave privada de los certfifcados X.509 para un certificado CA de root en las instalaciones de clientes diferentes, lo que facilita a atacantes man-in-the-middle falsificar servidores SSL nediante el aprovechamiento del conocimiento de esta clave, tal y como se informó originalmente para Superfish VisualDiscovery en ciertos productos portátiles de Lenovo Notebook."
    }
  ],
  "lastModified": "2026-06-17T00:23:33.413",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:komodia:redirector_sdk:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "567A899A-F2A5-4B5D-BA80-50705E62D375"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}