CVE-2013-2566
MEDIUMOracle Communications Application Session Controller 3.0.0-3.9.1 - Inadequate Encryption Strength via RC4 Algorithm
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-2566.
PoCs published by todb, et, Chris John Riley, including Metasploit module auxiliary/scanner/ssl/ssl_version.
AI-analyzed exploit summary This Metasploit module scans for SSL/TLS vulnerabilities, including CVE-2013-2566 (RC4 cipher weakness), by detecting supported protocols and cipher suites. It reports vulnerabilities like POODLE, DROWN, BEAST, and others without exploiting them.
Description
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.
Exploits (1)
This Metasploit module scans for SSL/TLS vulnerabilities, including CVE-2013-2566 (RC4 cipher weakness), by detecting supported protocols and cipher suites. It reports vulnerabilities like POODLE, DROWN, BEAST, and others without exploiting them.
References (21)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N