PT-2013-1151 · Openssl+9 · Openssl+11

Published

2013-12-01

·

Updated

2024-06-15

·

CVE-2014-3572

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 1.0.0p OpenSSL versions prior to 1.0.1k openssl-1.0.1e openssl-devel-1.0.1e openssl-static-1.0.1e openssl-libs-1.0.1e openssl-debuginfo-1.0.1e
Description The issue allows remote SSL servers to conduct ECDHE-to-ECDH downgrade attacks, triggering a loss of forward secrecy by omitting the ServerKeyExchange message. This can lead to a violation of the confidentiality and integrity of protected information. The vulnerability can be exploited remotely.
Recommendations For versions prior to 1.0.0p, update to version 1.0.0p or later. For versions prior to 1.0.1k, update to version 1.0.1k or later. For openssl-1.0.1e, consider disabling the ssl3 get key exchange function as a temporary workaround until a patch is available. For openssl-devel-1.0.1e, restrict access to the vulnerable module to minimize the risk of exploitation. For openssl-static-1.0.1e, avoid using the ServerKeyExchange message in the affected API endpoint until the issue is resolved. For openssl-libs-1.0.1e and openssl-debuginfo-1.0.1e, update to a newer version that contains a fix for this issue.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1023
ALT-PU-2015-2113
BDU:2015-06127
BDU:2015-06128
BDU:2015-06129
BDU:2015-06130
BDU:2015-06131
BDU:2015-09142
BDU:2015-09143
BDU:2015-09144
BDU:2015-09145
BDU:2015-09146
BDU:2015-09819
BDU:2015-09905
CESA-2015_0066
CVE-2014-3572
DLA-132-1
DSA-3125-1
HPSBUX03162
HPSBUX03244
MGASA-2015-0022
OPENSUSE-SU-2015_0130-1
OPENSUSE-SU-2015_1277-1
OPENSUSE-SU-2016_0640-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10309-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2015:0066
RHSA-2015_0066
SUSE-FU-2022:0445-1
SUSE-RU-2015:0769-1
SUSE-SU-2015:0182-2
SUSE-SU-2015:0305-1
SUSE-SU-2015:0543-1
SUSE-SU-2015:0545-1
SUSE-SU-2015:0545-2
SUSE-SU-2015:0546-1
SUSE-SU-2015:0547-1
SUSE-SU-2015:0578-1
SUSE-SU-2015:0620-1
SUSE-SU-2015:0946-1
SUSE-SU-2015:1177-1
SUSE-SU-2015:1182-1
SUSE-SU-2015:1182-2
SUSE-SU-2015:1183-1
SUSE-SU-2015:1183-2
SUSE-SU-2015:1184-1
SUSE-SU-2015:1184-2
SUSE-SU-2015:1185-1
SUSE-SU-403
USN-2459-1

Affected Products

Alt Linux
Centos
Cisco Ios
Cisco Ios Xe
Cisco Nexus
Hp-Ux
Ibm Aix
Junos
Openssl
Red Hat
Suse
Ubuntu