CVE-2015-8960, also known as "Key Compromise Impersonation (KCI)," is a vulnerability in TLS 1.2 and earlier that allows man-in-the-middle attackers to spoof TLS servers. This is possible because the protocol does not adequately document how to compute the master secret in specific scenarios involving a client secret key and server public key, but not a server secret key. This flaw impacts a wide range of products from vendors including Apple, Google, Microsoft, Mozilla, NetApp, and Opera. The vulnerability carries a high severity CVSS score of 8.1, indicating a critical risk. It has a network attack vector and high attack complexity, but successful exploitation could lead to high confidentiality, integrity, and availability impacts. The EPSS score is low, suggesting a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, nor are there publicly available Metasploit, Nuclei, or ExploitDB modules. Community discussion and media coverage for this CVE are minimal, indicating a lack of widespread attention or public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.2CPE matchmatch criteria | cpe:2.3:a:ietf:transport_layer_security:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:clustered_data_ontap_antivirus_connector:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:data_ontap_edge:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:host_agent:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:oncommand_shift:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.