CVE-2011-3389
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 73.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 73.33% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-326
- Affected
- google/chrome · microsoft/internet explorer · mozilla/firefox · opera/opera browser · microsoft/windows · siemens/simatic rf68xr firmware · siemens/simatic rf615r firmware · haxx/curl · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux workstation · debian/debian linux · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/Third Party Advisory
- http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspxThird Party Advisory
- http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspxThird Party Advisory
- http://curl.haxx.se/docs/adv_20120124B.htmlThird Party Advisory
- http://downloads.asterisk.org/pub/security/AST-2016-001.htmlThird Party Advisory
- http://ekoparty.org/2011/juliano-rizzo.phpBroken Link
- http://eprint.iacr.org/2004/111Third Party Advisory
- http://eprint.iacr.org/2006/136Third Party Advisory
- http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.htmlNot Applicable, Vendor Advisory
- http://isc.sans.edu/diary/SSL+TLS+part+3+/11635Third Party Advisory
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.htmlBroken Link
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.htmlBroken Link
- http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.htmlBroken Link, Mailing List
- http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.htmlBroken Link, Mailing List
- http://lists.apple.com/archives/security-announce/2012/May/msg00001.htmlBroken Link, Mailing List
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.htmlBroken Link, Mailing List
- http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.htmlBroken Link, Mailing List
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.htmlBroken Link
- http://marc.info/?l=bugtraq&m=132750579901589&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=132872385320240&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=133365109612558&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=133728004526190&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=134254866602253&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=134254957702612&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://my.opera.com/securitygroup/blog/2011/09/28/the-beast-ssl-tls-issueThird Party Advisory
- http://osvdb.org/74829Broken Link
- http://rhn.redhat.com/errata/RHSA-2012-0508.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.