« Volver al listado

CVE-2016-5774

Estado: ModificadaAlta (8.1)—

The HTTPS server in Blue Coat PacketShaper S-Series 11.5.x before 11.5.3.2 might allow remote attackers to obtain sensitive credentials and other information via unspecified vectors, related to use of insecure cryptographic parameters.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-5774",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2016-07-12T19:59:07.600",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/91455",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bto.bluecoat.com/security-advisory/sa127",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/91455",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bto.bluecoat.com/security-advisory/sa127",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The HTTPS server in Blue Coat PacketShaper S-Series 11.5.x before 11.5.3.2 might allow remote attackers to obtain sensitive credentials and other information via unspecified vectors, related to use of insecure cryptographic parameters."
    },
    {
      "lang": "es",
      "value": "El servidor HTTPS en Blue Coat PacketShaper S-Series 11.5.x en versiones anteriores a 11.5.3.2 podría permitir a atacantes remotos obtener credenciales sensibles y otra información a través de vectores no especificados, relacionado con el uso de parámetros criptográficos inseguros."
    }
  ],
  "lastModified": "2026-06-17T00:50:01.837",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:blue_coat:packetshaper_s-series:11.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "806043E5-CC83-4B82-B91E-91F2EB9CE671"
            },
            {
              "criteria": "cpe:2.3:a:blue_coat:packetshaper_s-series:11.5.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA3C17F6-C460-4DF9-B77E-5B10EDBAFEBA"
            },
            {
              "criteria": "cpe:2.3:a:blue_coat:packetshaper_s-series:11.5.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D292C3BD-25D1-4E80-9F44-86F696D35C58"
            },
            {
              "criteria": "cpe:2.3:a:blue_coat:packetshaper_s-series:11.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60A0B3F4-A297-4D77-9B76-247B2A75FA70"
            },
            {
              "criteria": "cpe:2.3:a:blue_coat:packetshaper_s-series:11.5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0CE4F4F7-B045-4924-9FF0-02E7B221D843"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}