CVE-2013-2566

The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.

medium 5.9 CVSS 3.0
Published: Mar 15, 2013
Modified: Apr 29, 2026
Vendor: Oracle
Product: Communications Application Session Controller
Versions: 11.1.1.7.0,11.1.1.9.0,12.1.3.0.0,12.2.1.1.0,12.2.1.2.0,12.04,12.10,13.04,13.10

Description

The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.

References

Related CVEs