← Back

CVE-2015-8960

nvd nist
Published: Sep 21, 2016Modified: May 6, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which makes it easier for man-in-the-middle attackers to spoof TLS servers by leveraging knowledge of the secret key for an arbitrary installed client X.509 certificate, aka the "Key Compromise Impersonation (KCI)" issue.

Affected (15)

1 product
Transport Layer Security
12 products
Data Ontap Edge
Host Agent
Oncommand Shift
Plug In For Symantec Netbackup
Smi S Provider
Snap Creator Framework
Snapdrive
Snapmanager
Snapprotect
Solidfire & Hci Management Node
System Setup
Configuration A
1 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
Up to 1.2
Running on/withPlatform Versions
Apple
Safari
All versions
Google
Chrome
All versions
Microsoft
Internet Explorer
All versions
Mozilla
Firefox
All versions
Opera
Opera Browser
All versions
Configuration B
14 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
Netapp
All versions
All versions
Netapp
All versions
All versions
All versions
All versions
All versions

References (12)

Source: secalert@redhat.com
Press/Media CoverageTechnical DescriptionThird Party Advisory
Source: secalert@redhat.com
Mailing ListTechnical DescriptionThird Party Advisory
Source: secalert@redhat.com
Broken LinkThird Party AdvisoryVDB Entry
Source: secalert@redhat.com
ExploitTechnical Description
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
ExploitMitigationTechnical Description
Source: af854a3a-2127-422b-91ae-364da2661108
Press/Media CoverageTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical Description
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationTechnical Description

Timeline

No history available yet.