SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-3389

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows…

MEDIUM 4.3EPSS 73.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 73.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS
73.33% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-326
Affected
google/chrome · microsoft/internet explorer · mozilla/firefox · opera/opera browser · microsoft/windows · siemens/simatic rf68xr firmware · siemens/simatic rf615r firmware · haxx/curl · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux workstation · debian/debian linux · canonical/ubuntu linux
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.