CVE-2013-2566: Weak Encryption

Published Mar 14, 2013
·
Updated

A new attack was discovered against TLS that allows an attacker to recover a limited amount of plaintext from a TLS connection when RC4 encryption is used. The attacks arise from statistical flaws in the keystream generated by the RC4 algorithm which become apparent in TLS ciphertexts when the same plaintext is repeatedly encrypted at a fixed location across many TLS sessions.

Reference:

http://www.isg.rhul.ac.uk/tls/ http://blog.cryptographyengineering.com/2013/03/attack-of-week-rc4-is-kind-of-broken-in.html

Other sources

The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.

Affected Software

58 affected components
GE Vulnerabilities related to SSH Support: firmware versions 7.4x to 8.0x (CyberSentry option)
GE Web server vulnerabilities: all firmware versions prior to version 8.1x
GE Protection from unintended firmware upload: all firmware versions prior to 8.1x with basic security option
GE Provisions to disable Factory Mode: all firmware versions prior to 8.1x with basic security option
GE Access to “Last-key pressed” register: all firmware versions prior to 8.1x with basic security option
GE Weakness in UR bootloader binary: all bootloader versions prior to 7.03/7.04
Oracle Communications Application Session Controller>=3.0.0<=3.9.1
Oracle HTTP Server=11.1.1.7.0
Oracle HTTP Server=11.1.1.9.0
Oracle HTTP Server=12.1.3.0.0
Oracle HTTP Server=12.2.1.1.0
Oracle HTTP Server=12.2.1.2.0
Oracle Integrated Lights Out Manager Firmware>=3.0.0<=3.2.11
Oracle Integrated Lights Out Manager Firmware>=4.0.0<=4.0.4
All of the following
Fujitsu Sparc Enterprise M3000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M3000
All of the following
Fujitsu Sparc Enterprise M4000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M4000
All of the following
Fujitsu Sparc Enterprise M5000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M5000
All of the following
Fujitsu Sparc Enterprise M8000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M8000
All of the following
Fujitsu Sparc Enterprise M9000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M9000
All of the following
Fujitsu M10-1 Firmware>=xcp<xcp2280
Fujitsu M10-1
All of the following
Fujitsu M10-4 Firmware>=xcp<xcp2280
Fujitsu M10-4
All of the following
Fujitsu M10-4s Firmware>=xcp<xcp2280
Fujitsu M10-4s
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=12.10
Canonical Ubuntu Linux=13.04
Canonical Ubuntu Linux=13.10
Mozilla Firefox<17.0.11
Mozilla Firefox<25.0.1
Mozilla Firefox>=24.1.0<24.1.1
Mozilla SeaMonkey<2.22.1
Mozilla Thunderbird<24.1.1
Mozilla Thunderbird ESR<17.0.11
Fujitsu Sparc Enterprise M3000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M3000
Fujitsu Sparc Enterprise M4000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M4000
Fujitsu Sparc Enterprise M5000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M5000
Fujitsu Sparc Enterprise M8000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M8000
Fujitsu Sparc Enterprise M9000 Firmware>=xcp<xcp_1121
Fujitsu Sparc Enterprise M9000
Fujitsu M10-1 Firmware>=xcp<xcp2280
Fujitsu M10-1
Fujitsu M10-4 Firmware>=xcp<xcp2280
Fujitsu M10-4
Fujitsu M10-4s Firmware>=xcp<xcp2280
Fujitsu M10-4s
Mozilla Firefox ESR<17.0.11
Mozilla Firefox ESR>=24.1.0<24.1.1

Event History

Mar 14, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Mar 15, 2013
Data Sourced
12:00 AM
RemedyDescriptionSeverity
Data Sourced
10:18 AM
Affected Software
Data Sourced
via NVD·09:55 PM
DescriptionSeverityWeaknessAffected Software
Sep 25, 58369
Event
via NVD·01:45 PM

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2013-2566?

CVE-2013-2566 is categorized as a medium severity vulnerability due to its potential to leak limited plaintext data from TLS connections using RC4 encryption.

2

How do I fix CVE-2013-2566?

To fix CVE-2013-2566, disable RC4 encryption in your TLS configuration and switch to a stronger cipher.

3

Which software is affected by CVE-2013-2566?

CVE-2013-2566 affects various software including GE firmware versions 7.4x to 8.0x and multiple versions of Oracle HTTP Server.

4

Can CVE-2013-2566 be exploited remotely?

Yes, CVE-2013-2566 can be exploited remotely if an attacker can intercept and manipulate the TLS traffic.

5

What encryption algorithm does CVE-2013-2566 target?

CVE-2013-2566 specifically targets the RC4 encryption algorithm used in TLS connections.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203