CVE-2015-8960: High severity transport layer security vulnerability
The TLS protocol 1.2 and earlier supports the rsafixeddh, dssfixeddh, rsafixedecdh, and ecdsafixedecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which makes it easier for man-in-the-middle attackers to spoof TLS servers by leveraging knowledge of the secret key for an arbitrary installed client X.509 certificate, aka the "Key Compromise Impersonation (KCI)" issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8960?
CVE-2015-8960 has a medium severity rating due to the potential risk of cryptographic vulnerabilities in the TLS protocol.
How do I fix CVE-2015-8960?
To fix CVE-2015-8960, update to a version of the TLS protocol that addresses the identified weaknesses, typically by upgrading to TLS 1.3 or later.
Which software is affected by CVE-2015-8960?
CVE-2015-8960 affects the IETF Transport Layer Security up to version 1.2, as well as certain NetApp software products.
Is CVE-2015-8960 exploitable in all environments?
CVE-2015-8960 is not universally exploitable and may depend on specific configurations and implementations of TLS.
What are the implications of CVE-2015-8960 for secure communications?
The implications of CVE-2015-8960 for secure communications include potential exposure to attacks that could compromise the confidentiality and integrity of data transmitted over TLS.