Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-10259

Опубликовано: 11 апр. 2017
Источник: nvd
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-of-service vulnerability that impacts the SSL servers for intercepted SSL connections. A malicious SSL client can, under certain circumstances, temporarily exhaust the TCP connection pool of an SSL server.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv1800_firmware:3.8.4:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv1800_firmware:3.9:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv1800_firmware:3.10:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv1800_firmware:3.11:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv1800_firmware:3.11.1.1:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv1800_firmware:3.11.1.2:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv1800_firmware:3.11.2.1:*:*:*:*:*:*:*
cpe:2.3:h:bluecoat:ssl_visibility_appliance_sv1800:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

Одно из

cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv800_firmware:3.8.4:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv800_firmware:3.9:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv800_firmware:3.10:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv800_firmware:3.11:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv800_firmware:3.11.1.1:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv800_firmware:3.11.1.2:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv800_firmware:3.11.2.1:*:*:*:*:*:*:*
cpe:2.3:h:bluecoat:ssl_visibility_appliance_sv800:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

Одно из

cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv3800_firmware:3.8.4:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv3800_firmware:3.9:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv3800_firmware:3.10:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv3800_firmware:3.11:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv3800_firmware:3.11.1.1:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv3800_firmware:3.11.1.2:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv3800_firmware:3.11.2.1:*:*:*:*:*:*:*
cpe:2.3:h:bluecoat:ssl_visibility_appliance_sv3800:-:*:*:*:*:*:*:*
Конфигурация 4

Одновременно

Одно из

cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv2800_firmware:3.8.4:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv2800_firmware:3.9:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv2800_firmware:3.10:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv2800_firmware:3.11:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv2800_firmware:3.11.1.1:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv2800_firmware:3.11.1.2:*:*:*:*:*:*:*
cpe:2.3:o:bluecoat:ssl_visibility_appliance_sv2800_firmware:3.11.2.1:*:*:*:*:*:*:*
cpe:2.3:h:bluecoat:ssl_visibility_appliance_sv2800:-:*:*:*:*:*:*:*

EPSS

Процентиль: 64%
0.0046
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-399

Связанные уязвимости

CVSS3: 5.9
github
больше 3 лет назад

Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-of-service vulnerability that impacts the SSL servers for intercepted SSL connections. A malicious SSL client can, under certain circumstances, temporarily exhaust the TCP connection pool of an SSL server.

EPSS

Процентиль: 64%
0.0046
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-399