CVE-2015-8960
Last modified
CVE-2015-8960 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which makes it easier for man-in-the-middle attackers to spoof TLS servers by leveraging knowledge of the secret key for an arbitrary installed client X.509 certificate, aka the "Key Compromise Impersonation (KCI)" issue.. EPSS estimates a 1.95% chance of exploitation in the next 30 days.
Description
The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which makes it easier for man-in-the-middle attackers to spoof TLS servers by leveraging knowledge of the secret key for an arbitrary installed client X.509 certificate, aka the "Key Compromise Impersonation (KCI)" issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ietf | Transport Layer Security | <= 1.2 |
| Netapp | Clustered Data Ontap Antivirus Connector | All versions |
| Netapp | Data Ontap Edge | All versions |
| Netapp | Host Agent | All versions |
| Netapp | Oncommand Shift | All versions |
| Netapp | Plug-In For Symantec Netbackup | All versions |
| Netapp | Smi-S Provider | All versions |
| Netapp | Snap Creator Framework | All versions |
| Netapp | Snapdrive | All versions |
| Netapp | Snapmanager | All versions |
| Netapp | Snapprotect | All versions |
| Netapp | Solidfire \& Hci Management Node | All versions |
| Netapp | System Setup | All versions |
References
- https://twitter.com/matthew_d_green/statuses/630908726950674433Press/Media Coverage, Technical Description, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2016/09/20/4Mailing List, Technical Description, Third Party Advisory
- https://www.securityfocus.com/bid/93071Broken Link, Third Party Advisory, VDB Entry
- https://kcitls.orgExploit, Technical Description
- https://security.netapp.com/advisory/ntap-20180626-0002/Third Party Advisory
- https://www.usenix.org/system/files/conference/woot15/woot15-paper-hlauschek.pdfExploit, Mitigation, Technical Description
- https://twitter.com/matthew_d_green/statuses/630908726950674433Press/Media Coverage, Technical Description, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2016/09/20/4Mailing List, Technical Description, Third Party Advisory
- https://www.securityfocus.com/bid/93071Broken Link, Third Party Advisory, VDB Entry
- https://kcitls.orgExploit, Technical Description
- https://security.netapp.com/advisory/ntap-20180626-0002/Third Party Advisory
- https://www.usenix.org/system/files/conference/woot15/woot15-paper-hlauschek.pdfExploit, Mitigation, Technical Description
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-8960?
How severe is CVE-2015-8960?
How do I fix CVE-2015-8960?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-8954The MemcmpLowercase function in Suricata before 2.0.6 improp…
- CVE-2015-8955arch/arm64/kernel/perf_event.c in the Linux kernel before 4.…7.3
- CVE-2015-8956The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c…
- CVE-2015-8957Buffer overflow in ImageMagick before 6.9.0-4 Beta allows re…
- CVE-2015-8958coders/sun.c in ImageMagick before 6.9.0-4 Beta allows remot…
- CVE-2015-8959coders/dds.c in ImageMagick before 6.9.0-4 Beta allows remot…6.5
- CVE-2015-8961The __ext4_journal_stop function in fs/ext4/ext4_jbd2.c in t…7.8
- CVE-2015-8962Double free vulnerability in the sg_common_write function in…7.3
- CVE-2015-8963Race condition in kernel/events/core.c in the Linux kernel b…7
- CVE-2015-8964The tty_set_termios_ldisc function in drivers/tty/tty_ldisc.…
- CVE-2015-8965Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1…9.8
- CVE-2015-8966arch/arm/kernel/sys_oabi-compat.c in the Linux kernel before…
Are you affected by CVE-2015-8960?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
