Vulnerabilities > CVE-2017-18268 - Information Exposure Through Discrepancy vulnerability in Broadcom Symantec Intelligencecenter 3.3

047910
CVSS 5.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
high complexity
broadcom
CWE-203

Summary

Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote attacker, who has captured a pre-recorded SSL session inspected by SSLV, can establish large numbers of crafted SSL connections to the target and obtain the session keys required to decrypt the pre-recorded SSL session.

Vulnerable Configurations

Part Description Count
Application
Broadcom
1

Common Weakness Enumeration (CWE)