CVE-2017-15533 PUBLISHED CVSS 5.900000095367432 MEDIUM

Symantec SSL Visibility (SSLV) 3.8.4FC, 3.10 prior to 3.10.4.1, 3.11, and 3.12 prior to 3.12.2.1 are vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. All affected SSLV versions act as weak oracles according the oracle classification used in the ROBOT research paper. A remote attacker, who has captured a pre-recorded SSL session inspected by SSLV, can establish multiple millions of crafted SSL connections to the target and obtain the session keys required to decrypt the pre-recorded SSL session.

EPSS 0.28% · 51.5th percentile

Risk Scores

CVSS v3.0
5.900000095367432
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.28%
51.5th percentile

Affected Products

VendorProductVersions
broadcomssl_visibility_appliance3.12, 3.8.4fc, 3.10
Symantec CorporationSSL Visibility (SSLV)3.8.4FC, 3.10 prior to 3.10.4.1, 3.11

Timeline

References

Open in Interactive Console →