CVE-2013-2566mediumCWE-327

CVE-2013-2566

Published · Updated

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 5.9epss 84%
from disclosure to weapon579 days
Published on NVDMar 14
metasploit+579d
exploitation probability
84%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
2 products (19 components)
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 5
no_fix_planned: Will not fix
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/a