CVE-2013-2566

MEDIUM

Oracle Communications Application Session Controller 3.0.0-3.9.1 - Inadequate Encryption Strength via RC4 Algorithm

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-2566. PoCs published by todb, et, Chris John Riley, including Metasploit module auxiliary/scanner/ssl/ssl_version.

AI-analyzed exploit summary This Metasploit module scans for SSL/TLS vulnerabilities, including CVE-2013-2566 (RC4 cipher weakness), by detecting supported protocols and cipher suites. It reports vulnerabilities like POODLE, DROWN, BEAST, and others without exploiting them.

Description

The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.

Exploits (1)

metasploit SCANNER
by todb, et, Chris John Riley · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/ssl/ssl_version.rb

This Metasploit module scans for SSL/TLS vulnerabilities, including CVE-2013-2566 (RC4 cipher weakness), by detecting supported protocols and cipher suites. It reports vulnerabilities like POODLE, DROWN, BEAST, and others without exploiting them.

Classification
Scanner 100%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: SSL/TLS servers (various versions)
No auth needed
Prerequisites: Network access to target server · SSL/TLS service running on target
mistral-large-3 · analyzed Jun 17, 2026 Full analysis →

References (21)

Core 21
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/58796
Third Party Advisory x_refsource_misc
http://cr.yp.to/talks/2013.03.12/slides.pdf
Issue Tracking, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=143039468003789&w=2
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201504-01
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201406-19.xml
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2031-1
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2032-1
Third Party Advisory x_refsource_confirm
http://www.opera.com/security/advisory/1046
Third Party Advisory x_refsource_confirm
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
Third Party Advisory x_refsource_confirm
http://www.mozilla.org/security/announce/2013/mfsa2013-103.html
Third Party Advisory x_refsource_misc
http://www.isg.rhul.ac.uk/tls/
Third Party Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/unified/1215/

Scores

CVSS v3 5.9
EPSS 0.8442
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-326 CWE-327
Status published
Products (23)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 12.10
canonical/ubuntu_linux 13.04
canonical/ubuntu_linux 13.10
fujitsu/m10-1_firmware xcp - xcp2280
fujitsu/m10-4_firmware xcp - xcp2280
fujitsu/m10-4s_firmware xcp - xcp2280
fujitsu/sparc_enterprise_m3000_firmware xcp - xcp_1121
fujitsu/sparc_enterprise_m4000_firmware xcp - xcp_1121
fujitsu/sparc_enterprise_m5000_firmware xcp - xcp_1121
... and 13 more
Published Mar 15, 2013
Tracked Since Feb 18, 2026