CVE-2015-2808

low
Published 2015-04-01 ยท Modified 2026-05-28
CVSS v3
3.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
3.7

Description

The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.

Predictions

Exploit likelihood
47%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

redhat Red Hat Affected 11 releases
VersionStatusFixed in
7.7 Affected โ€”
7.6 Affected โ€”
7.5 Affected โ€”
7.4 Affected โ€”
7.3 Affected โ€”
7.2 Affected โ€”
7.1 Affected โ€”
7.0 Affected โ€”
6.6 Affected โ€”
6.0 Affected โ€”
5.0 Affected โ€”
suse SUSE Affected 6 releases
VersionStatusFixed in
13.2 Affected โ€”
13.1 Affected โ€”
12 Affected โ€”
11 Affected โ€”
10 Affected โ€”
โ€” Affected โ€”
ubuntu Ubuntu Affected 3 releases
VersionStatusFixed in
15.04 Affected โ€”
14.04 Affected โ€”
12.04 Affected โ€”
debian Debian Mixed 3 releases
VersionStatusFixed in
sid Fixed 8u66-b01-1
8.0 Affected โ€”
7.0 Affected โ€”

Application impact

VendorProductVersionsFixed
oracle oraclecommunications_application_session_controller{"startIncluding":"3.0.0","endIncluding":"3.9.0"}
oracle oraclecommunications_policy_management{"endExcluding":"9.9.2"}9.9.2
oracle oraclehttp_server11.1.1.7.0
oracle oraclehttp_server11.1.1.9.0
oracle oraclehttp_server12.1.3.0.0
oracle oraclehttp_server12.2.1.1.0
oracle oraclehttp_server12.2.1.2.0
redhat redhatsatellite5.7
suse suselinux_enterprise_debuginfo11
suse susemanager1.7
redhat redhatsatellite5.6
huawei huaweioceanstor_replicationdirectorv100r003c00
huawei huaweipolicy_centerv100r003c00
huawei huaweipolicy_centerv100r003c10
huawei huaweismc2.0v100r002c01
huawei huaweismc2.0v100r002c02
huawei huaweismc2.0v100r002c03
huawei huaweismc2.0v100r002c04
huawei huaweiultravrv100r003c00
ibm ibmcognos_metrics_manager10.1
ibm ibmcognos_metrics_manager10.1.1
ibm ibmcognos_metrics_manager10.2
ibm ibmcognos_metrics_manager10.2.1
ibm ibmcognos_metrics_manager10.2.2
fujitsusparc_enterprise_m3000-
fujitsusparc_enterprise_m4000-
fujitsusparc_enterprise_m5000-
fujitsusparc_enterprise_m8000-
fujitsusparc_enterprise_m9000-
huawei huaweie6000-
huawei huaweie9000-
huawei huaweioceanstor_18500-
huawei huaweioceanstor_18800-
huawei huaweioceanstor_18800f-
huawei huaweioceanstor_9000-
huawei huaweioceanstor_cse-
huawei huaweioceanstor_hvs85t-
huawei huaweioceanstor_s2600t-
huawei huaweioceanstor_s5500t-
huawei huaweioceanstor_s5600t-
huawei huaweioceanstor_s5800t-
huawei huaweioceanstor_s6800t-
huawei huaweioceanstor_vis6600t-
huawei huaweiquidway_s9300-
huawei huaweis7700-
huawei huawei9700-
huawei huaweis12700-
huawei huaweis2700-
huawei huaweis3700-
huawei huaweis5700ei-
huawei huaweis5700hi-
huawei huaweis5700si-
huawei huaweis5710ei-
huawei huaweis5710hi-
huawei huaweis6700-
huawei huaweis2750-
huawei huaweis5700li-
huawei huaweis5700s-li-
huawei huaweis5720hi-
huawei huaweis5720ei-
huawei huaweite60-

References

CWEs

CWE-327

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.