SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-4180

OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an…

MEDIUM 4.3EPSS 9.50%

Does this matter?

Lower severity and a low EPSS score (9.50%). Track it; it rarely justifies an emergency change on its own.

Description

OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
9.50% probability · 95th percentile
CISA KEV
Not listed
Affected
openssl/openssl · fedoraproject/fedora · debian/debian linux · canonical/ubuntu linux · opensuse/opensuse · suse/linux enterprise · suse/linux enterprise desktop · suse/linux enterprise server · f5/nginx
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.