CVE-2013-2566

MEDIUM

Oracle Communications Application Session Controller 3.0.0-3.9.1 - Inadequate Encryption Strength via RC4 Algorithm

Title source: llm
STIX 2.1

Description

The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.

References (21)

Core 21
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/58796
Third Party Advisory x_refsource_misc
http://cr.yp.to/talks/2013.03.12/slides.pdf
Issue Tracking, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=143039468003789&w=2
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201504-01
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201406-19.xml
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2031-1
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2032-1
Third Party Advisory x_refsource_confirm
http://www.opera.com/security/advisory/1046
Third Party Advisory x_refsource_confirm
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
Third Party Advisory x_refsource_confirm
http://www.mozilla.org/security/announce/2013/mfsa2013-103.html
Third Party Advisory x_refsource_misc
http://www.isg.rhul.ac.uk/tls/
Third Party Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/unified/1215/

Scores

CVSS v3 5.9
EPSS 0.8442
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-326 CWE-327
Status published
Products (23)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 12.10
canonical/ubuntu_linux 13.04
canonical/ubuntu_linux 13.10
fujitsu/m10-1_firmware xcp - xcp2280
fujitsu/m10-4_firmware xcp - xcp2280
fujitsu/m10-4s_firmware xcp - xcp2280
fujitsu/sparc_enterprise_m3000_firmware xcp - xcp_1121
fujitsu/sparc_enterprise_m4000_firmware xcp - xcp_1121
fujitsu/sparc_enterprise_m5000_firmware xcp - xcp_1121
... and 13 more
Published Mar 15, 2013
Tracked Since Feb 18, 2026