CVE-2015-8960

HIGHCVSS 8.1/10EPSS 1.95%

Last modified

CVE-2015-8960 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which makes it easier for man-in-the-middle attackers to spoof TLS servers by leveraging knowledge of the secret key for an arbitrary installed client X.509 certificate, aka the "Key Compromise Impersonation (KCI)" issue.. EPSS estimates a 1.95% chance of exploitation in the next 30 days.

Description

The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which makes it easier for man-in-the-middle attackers to spoof TLS servers by leveraging knowledge of the secret key for an arbitrary installed client X.509 certificate, aka the "Key Compromise Impersonation (KCI)" issue.

Metrics

CVSS 3.1
8.1/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.95%

77.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IetfTransport Layer Security<= 1.2
NetappClustered Data Ontap Antivirus ConnectorAll versions
NetappData Ontap EdgeAll versions
NetappHost AgentAll versions
NetappOncommand ShiftAll versions
NetappPlug-In For Symantec NetbackupAll versions
NetappSmi-S ProviderAll versions
NetappSnap Creator FrameworkAll versions
NetappSnapdriveAll versions
NetappSnapmanagerAll versions
NetappSnapprotectAll versions
NetappSolidfire \& Hci Management NodeAll versions
NetappSystem SetupAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-8960?
The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which makes it easier for man-in-the-middle attackers to spoof TLS servers by leveraging knowledge of the secret key for an arbitrary installed client X.509 certificate, aka the "Key Compromise Impersonation (KCI)" issue.
How severe is CVE-2015-8960?
CVE-2015-8960 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 1.95% probability of exploitation in the next 30 days.
How do I fix CVE-2015-8960?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-8960?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST