CVE-2009-3555
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 87.3%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 87.26% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295, CWE-300
- Affected
- apache/http server · gnu/gnutls · mozilla/nss · openssl/openssl · canonical/ubuntu linux · debian/debian linux · fedoraproject/fedora · f5/nginx
- Source
- secalert@redhat.com
References
- http://archives.neohapsis.com/archives/bugtraq/2013-11/0120.htmlBroken Link
- http://blog.g-sec.lu/2009/11/tls-sslv3-renegotiation-vulnerability.htmlThird Party Advisory
- http://blogs.iss.net/archive/sslmitmiscsrf.htmlBroken Link
- http://blogs.sun.com/security/entry/vulnerability_in_tls_protocol_duringThird Party Advisory
- http://clicky.me/tlsvulnExploit, Third Party Advisory
- http://extendedsubset.com/?p=8Broken Link
- http://extendedsubset.com/Renegotiating_TLS.pdfBroken Link
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686Broken Link
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02436041Broken Link
- http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751Broken Link
- http://kbase.redhat.com/faq/docs/DOC-20491Third Party Advisory
- http://lists.apple.com/archives/security-announce/2010//May/msg00001.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2010//May/msg00002.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049455.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049528.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049702.htmlThird Party Advisory
- http://lists.gnu.org/archive/html/gnutls-devel/2009-11/msg00029.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00009.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00005.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.