Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-2987

12
FAUCET Score

CVE-2015-2987 describes a vulnerability in Type74 ED before version 4.0, where it improperly uses 128-bit ECB encryption for small files. This misconfiguration allows attackers to potentially recover plaintext data through differential cryptanalysis, particularly for files smaller than 128 bits. The vulnerability has a low CVSS score of 2.6, indicating a network attack vector with high attack complexity and a partial impact on confidentiality. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.4CPE matchmatch criteria
cpe:2.3:a:type74:ed:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

2.6LOW

AV:N/AC:H/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
4.9
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.69%
Probability of exploitation in next 30 days
EPSS Percentile
49.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0069 is in the 31st percentile among its peer group of 1,506 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (31)

microsoftpatch availablevia msrc
Product: azl3 ed 1.20-1 on Azure Linux 3.0Fixed in: 1.20-1
microsoftpatch availablevia msrc
Product: cm1 ed 1.14.2-8 on CBL Mariner 1.0Fixed in: 1.14.2-8
microsoftpatch availablevia msrc
Product: cbl2 ed 1.14.2-9 on CBL Mariner 2.0Fixed in: 1.14.2-9
microsoftpatch availablevia msrc
Product: 16830-17084Fixed in: 1.20-1
microsoftpatch availablevia msrc
Product: 16830-16817Fixed in: 1.20-1
microsoftpatch availablevia msrc
Product: 16828-16820Fixed in: 1.14.2-8
microsoftpatch availablevia msrc
Product: 16829-16823Fixed in: 1.14.2-9
microsoftpatch availablevia msrc
Product: 12883-12137Fixed in: 1.14.2-8
microsoftpatch availablevia msrc
Product: 12884-12137Fixed in: 1.14.2-8
microsoftpatch availablevia msrc
Product: 12885-12138Fixed in: 1.14.2-8
microsoftpatch availablevia msrc
Product: 12886-12138Fixed in: 1.14.2-8
microsoftpatch availablevia msrc
Product: 12887-12139Fixed in: 1.14.2-9
microsoftpatch availablevia msrc
Product: 12888-12139Fixed in: 1.14.2-9
microsoftpatch availablevia msrc
Product: 12889-12140Fixed in: 1.14.2-9
microsoftpatch availablevia msrc
Product: 12890-12140Fixed in: 1.14.2-9
microsoftpatch availablevia msrc
Product: 12891-12356Fixed in: 1.20-1
microsoftpatch availablevia msrc
Product: 12892-12357Fixed in: 1.20-1
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 1.14.2-8
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 1.14.2-8
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 1.14.2-9
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 1.14.2-9
microsoftpatch availablevia msrc
Product: ed-1.14.2-8.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 1.14.2-8
microsoftpatch availablevia msrc
Product: ed-debuginfo-1.14.2-8.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 1.14.2-8
microsoftpatch availablevia msrc
Product: ed-1.14.2-8.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 1.14.2-8
microsoftpatch availablevia msrc
Product: ed-debuginfo-1.14.2-8.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 1.14.2-8
microsoftpatch availablevia msrc
Product: ed-1.14.2-9.cm2.x86_64.rpm on CBL Mariner 2.0 x64Fixed in: 1.14.2-9
microsoftpatch availablevia msrc
Product: ed-debuginfo-1.14.2-9.cm2.x86_64.rpm on CBL Mariner 2.0 x64Fixed in: 1.14.2-9
microsoftpatch availablevia msrc
Product: ed-1.14.2-9.cm2.aarch64.rpm on CBL Mariner 2.0 ARMFixed in: 1.14.2-9
microsoftpatch availablevia msrc
Product: ed-debuginfo-1.14.2-9.cm2.aarch64.rpm on CBL Mariner 2.0 ARMFixed in: 1.14.2-9
microsoftpatch availablevia msrc
Product: ed-1.20-1.azl3.x86_64.rpm on Azure Linux 3.0 x64Fixed in: 1.20-1
microsoftpatch availablevia msrc
Product: ed-1.20-1.azl3.aarch64.rpm on Azure Linux 3.0 ARMFixed in: 1.20-1

Vendor Advisories (3)

microsoft2024-Jun/CVE-2015-2987

CVE-2015-2987

Jun 11, 2024
microsoft2020-Aug/CVE-2015-2987

CVE-2015-2987

Aug 11, 2020
microsoft2015-Aug/CVE-2015-2987Low

Type74 ED before 4.0 misuses 128-bit ECB encryption for small files which makes it easier for attackers to obtain plaintext data via differential cryptanalysis of a file with an original length smaller than 128 bits.

Aug 2, 2015

References

jvndb.jvn.jp / jvndb/JVNDB-2015-000119
Vendor Advisory
jvn.jp / en/jp/JVN91474878/index.html
Vendor Advisory
type74org.blog14.fc2.com / blog-entry-1384.html
Vendor Advisory
type74.org / edman5-1.php
PatchVendor Advisory