CVE-2015-2808 - CVE House
Back to Database
Status published Unknown CVE-2015-2808

The RC4 algorithm, as used in the TLS protocol and...

Vulnerability Description

The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-2808

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

communications application session controller, communications policy management, http server, integrated lights out manager firmware, debian linux, satellite, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server tus, enterprise linux workstation, linux enterprise debuginfo, opensuse, linux enterprise desktop, linux enterprise server, linux enterprise software development kit, manager, ubuntu linux, sparc enterprise m3000 firmware, sparc enterprise m4000 firmware, sparc enterprise m5000 firmware, sparc enterprise m8000 firmware, sparc enterprise m9000 firmware, e6000 firmware, e9000 firmware, oceanstor 18500 firmware, oceanstor 18800 firmware, oceanstor 18800f firmware, oceanstor 9000 firmware, oceanstor cse firmware, oceanstor hvs85t firmware, oceanstor s2600t firmware, oceanstor s5500t firmware, oceanstor s5600t firmware, oceanstor s5800t firmware, oceanstor s6800t firmware, oceanstor vis6600t firmware, quidway s9300 firmware, s7700 firmware, 9700 firmware, s12700 firmware, s2700 firmware, s3700 firmware, s5700ei firmware, s5700hi firmware, s5700si firmware, s5710ei firmware, s5710hi firmware, s6700 firmware, s2750 firmware, s5700li firmware, s5700s-li firmware, s5720hi firmware, s5720ei firmware, te60 firmware, oceanstor replicationdirector, policy center, smc2.0, ultravr, cognos metrics manager
Vulnerable Versions:
3.0.0, 0, 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0, 4.0.0, 7.0, 8.0, 5.7, 5.6, 5.0, 6.0, 6.6, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.7, 11, 13.1, 13.2, 12, 10, 1.7, 12.04, 14.04, 15.04, xcp, v100r003c00, v100r003c10, v100r002c01, v100r002c02, v100r002c03, v100r002c04, 10.1, 10.1.1, 10.2, 10.2.1, 10.2.2

Timeline

Official Publish: April 1st, 2015
Last Modified: May 28th, 2026
Added to House: July 19th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.