SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-0190

A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service.

HIGH 7.5EPSS 59.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 59.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
59.05% probability · 99th percentile
CISA KEV
Not listed
Affected
apache/http server · oracle/enterprise manager ops center · oracle/hospitality guest access · oracle/instantis enterprisetrack · oracle/retail xstore point of service
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.