383
VMScore

CVE-2017-15533

Published: 17/05/2018 Updated: 02/07/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Symantec SSL Visibility (SSLV) 3.8.4FC, 3.10 before 3.10.4.1, 3.11, and 3.12 before 3.12.2.1 are vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. All affected SSLV versions act as weak oracles according the oracle classification used in the ROBOT research paper. A remote attacker, who has captured a pre-recorded SSL session inspected by SSLV, can establish multiple millions of crafted SSL connections to the target and obtain the session keys required to decrypt the pre-recorded SSL session.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

broadcom ssl visibility appliance 3.10

broadcom ssl visibility appliance 3.12

broadcom ssl visibility appliance 3.8.4fc

broadcom ssl visibility appliance 3.11

Vendor Advisories

On December 12, 2017, a research paper with the title Return of Bleichenbacher's Oracle Threat was made publicly available This paper describes how some Transport Layer Security (TLS) stacks are vulnerable to variations of the classic Bleichenbacher attack on RSA key exchange Multiple vulnerabilities were identified based on this research An a ...