The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which makes it easier for man-in-the-middle attackers to spoof TLS servers by leveraging knowledge of the secret key for an arbitrary installed client X.509 certificate, aka the "Key Compromise Impersonation (KCI)" issue.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HApple Safari
APPAppleall versionsGoogle Chrome
APPGoogleall versionsIetf Transport Layer Security
APPIetf≤ 1.2Microsoft Internet Explorer
APPMicrosoftall versionsMozilla Firefox
APPMozillaall versionsNetapp Clustered Data Ontap Antivirus Connector
APPNetappall versionsNetapp Data Ontap Edge
APPNetappall versionsNetapp Host Agent
APPNetappall versionsNetapp Oncommand Shift
APPNetappall versionsNetapp Plug In For Symantec Netbackup
APPNetappall versionsNetapp Smi S Provider
APPNetappall versionsNetapp Snap Creator Framework
APPNetappall versionsNetapp Snapdrive
APPNetappall versionsNetapp Snapmanager
APPNetappall versionsNetapp Snapprotect
APPNetappall versionsNetapp Solidfire \& Hci Management Node
APPNetappall versionsNetapp System Setup
APPNetappall versionsOpera Browser
APPOperaall versions
Related vulnerabilities
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki
Use-after-free w Animation timelines Firefox/Thunderbird — RCE
Type confusion w V8 (Google Chrome/Edge) umożliwiający heap corruption
Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML