« Volver al listado

CVE-2015-8960

Estado: ModificadaAlta (8.1)—

The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which makes it easier for man-in-the-middle attackers to spoof TLS servers by leveraging knowledge of the secret key for an arbitrary installed client X.509 certificate, aka the "Key Compromise Impersonation (KCI)" issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (13)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-8960",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2016-09-21T02:59:00.133",
  "references": [
    {
      "url": "http://twitter.com/matthew_d_green/statuses/630908726950674433",
      "tags": [
        "Press/Media Coverage",
        "Technical Description",
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2016/09/20/4",
      "tags": [
        "Mailing List",
        "Technical Description",
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/93071",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://kcitls.org",
      "tags": [
        "Exploit",
        "Technical Description"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20180626-0002/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://www.usenix.org/system/files/conference/woot15/woot15-paper-hlauschek.pdf",
      "tags": [
        "Exploit",
        "Mitigation",
        "Technical Description"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://twitter.com/matthew_d_green/statuses/630908726950674433",
      "tags": [
        "Press/Media Coverage",
        "Technical Description",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2016/09/20/4",
      "tags": [
        "Mailing List",
        "Technical Description",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/93071",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://kcitls.org",
      "tags": [
        "Exploit",
        "Technical Description"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20180626-0002/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.usenix.org/system/files/conference/woot15/woot15-paper-hlauschek.pdf",
      "tags": [
        "Exploit",
        "Mitigation",
        "Technical Description"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-295"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which makes it easier for man-in-the-middle attackers to spoof TLS servers by leveraging knowledge of the secret key for an arbitrary installed client X.509 certificate, aka the \"Key Compromise Impersonation (KCI)\" issue."
    },
    {
      "lang": "es",
      "value": "El protocolo TLS 1.2 y versiones anteriores soporta los valores rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh y ecdsa_fixed_ecdh para ClientCertificateType pero no documenta directamente la habilidad para computar el secreto maestro en determinadas situaciones con una clave de cliente secreta y una clave pública de servidor pero no una clave secreta de servidor, lo que facilita a atacantes man-in-the-middle suplantar servidores TLS aprovechando el conocimiento de la clave secreta para un certificado cliente X.509 arbitrariamente instalado, también conocido como problema \"Key Compromise Impersonation (KCI)\"."
    }
  ],
  "lastModified": "2026-06-17T00:35:34.183",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ietf:transport_layer_security:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B20CCEB2-5534-4263-ACEA-C0A928CB6414",
              "versionEndIncluding": "1.2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apple:safari:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AFDA34B4-65B4-41A5-AC22-667C8D8FF4B7"
            },
            {
              "criteria": "cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "39B565E1-C2F1-44FC-A517-E3130332B17C"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C37BA825-679F-4257-9F2B-CE2318B75396"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "97D4FFCF-5309-43B6-9FD5-680C6D535A7F"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4545786D-3129-4D92-B218-F4A92428ED48"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:netapp:clustered_data_ontap_antivirus_connector:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62347994-1353-497C-9C4A-D5D8D95F67E8"
            },
            {
              "criteria": "cpe:2.3:a:netapp:data_ontap_edge:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0C4B1E5-75BF-43AE-BBAC-0DD4124C71ED"
            },
            {
              "criteria": "cpe:2.3:a:netapp:host_agent:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "546855F3-654C-48F0-B3A0-FF1ABBF04007"
            },
            {
              "criteria": "cpe:2.3:a:netapp:oncommand_shift:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3BD81527-A341-42C3-9AB9-880D3DB04B08"
            },
            {
              "criteria": "cpe:2.3:a:netapp:plug-in_for_symantec_netbackup:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FFE0A9D2-9A49-4BF6-BC6F-8249162D8334"
            },
            {
              "criteria": "cpe:2.3:a:netapp:smi-s_provider:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BB0FDCF-3750-44C6-AC5C-0CC2AAD14093"
            },
            {
              "criteria": "cpe:2.3:a:netapp:snap_creator_framework:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F4754FB-E3EB-454A-AB1A-AE3835C5350C"
            },
            {
              "criteria": "cpe:2.3:a:netapp:snapdrive:-:*:*:*:*:unix:*:*",
              "vulnerable": true,
              "matchCriteriaId": "61D7EF01-F618-497F-9375-8003CEA3D380"
            },
            {
              "criteria": "cpe:2.3:a:netapp:snapdrive:-:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BEDE62C6-D571-4AF8-B85E-CBBCE4AF98B5"
            },
            {
              "criteria": "cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:oracle:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26A2B713-7D6D-420A-93A4-E0D983C983DF"
            },
            {
              "criteria": "cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:sap:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64DE38C8-94F1-4860-B045-F33928F676A8"
            },
            {
              "criteria": "cpe:2.3:a:netapp:snapprotect:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F74F467A-0C81-40D9-BA06-40FB8EF02C04"
            },
            {
              "criteria": "cpe:2.3:a:netapp:solidfire_\\&_hci_management_node:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D6D700C5-F67F-4FFB-BE69-D524592A3D2E"
            },
            {
              "criteria": "cpe:2.3:a:netapp:system_setup:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "459CF8B6-B815-42EA-A286-6E737529D9AC"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}