CVE-2015-8960
The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.95%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which makes it easier for man-in-the-middle attackers to spoof TLS servers by leveraging knowledge of the secret key for an arbitrary installed client X.509 certificate, aka the "Key Compromise Impersonation (KCI)" issue.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.95% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- ietf/transport layer security · netapp/clustered data ontap antivirus connector · netapp/data ontap edge · netapp/host agent · netapp/oncommand shift · netapp/plug-in for symantec netbackup · netapp/smi-s provider · netapp/snap creator framework · netapp/snapdrive · netapp/snapmanager · netapp/snapprotect · netapp/solidfire \& hci management node · netapp/system setup
- Source
- secalert@redhat.com
References
- http://twitter.com/matthew_d_green/statuses/630908726950674433Press/Media Coverage, Technical Description, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/09/20/4Mailing List, Technical Description, Third Party Advisory
- http://www.securityfocus.com/bid/93071Broken Link, Third Party Advisory, VDB Entry
- https://kcitls.orgExploit, Technical Description
- https://security.netapp.com/advisory/ntap-20180626-0002/Third Party Advisory
- https://www.usenix.org/system/files/conference/woot15/woot15-paper-hlauschek.pdfExploit, Mitigation, Technical Description
- http://twitter.com/matthew_d_green/statuses/630908726950674433Press/Media Coverage, Technical Description, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/09/20/4Mailing List, Technical Description, Third Party Advisory
- http://www.securityfocus.com/bid/93071Broken Link, Third Party Advisory, VDB Entry
- https://kcitls.orgExploit, Technical Description
- https://security.netapp.com/advisory/ntap-20180626-0002/Third Party Advisory
- https://www.usenix.org/system/files/conference/woot15/woot15-paper-hlauschek.pdfExploit, Mitigation, Technical Description
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.