Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2015-2808 Details

Description

The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04779034 CVEThird Party Advisory
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 CVEThird Party Advisory
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10727 CVEThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.html CVEMailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.html CVEMailing ListThird Party Advisory

see all 202 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-327Use of a Broken or Risky Cryptographic Algorithm[email protected]
CWE-327Use of a Broken or Risky Cryptographic AlgorithmCISA-ADP

Affected Products

ProductVersions

Change History

45 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2015-2808
NVD Published Date:
Apr 1, 2015
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2015-2808 Details - Not Deferred