SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-10259

Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-of-service vulnerability that impacts the SSL servers for intercepted SSL connections.

MEDIUM 5.9EPSS 1.45%

Does this matter?

Lower severity and a low EPSS score (1.45%). Track it; it rarely justifies an emergency change on its own.

Description

Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-of-service vulnerability that impacts the SSL servers for intercepted SSL connections. A malicious SSL client can, under certain circumstances, temporarily exhaust the TCP connection pool of an SSL server.

CVSS 3.0
5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
1.45% probability · 72th percentile
CISA KEV
Not listed
Weakness
CWE-399
Affected
bluecoat/ssl visibility appliance sv1800 firmware · bluecoat/ssl visibility appliance sv800 firmware · bluecoat/ssl visibility appliance sv3800 firmware · bluecoat/ssl visibility appliance sv2800 firmware
Source
secure@symantec.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.