PT-2015-1696 · Ietf+11 · Tls+12

Published

2014-10-24

·

Updated

2026-05-27

·

CVE-2015-4000

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions TLS protocol versions 1.2 and earlier
Description The issue concerns a problem with the TLS protocol where a DHE EXPORT ciphersuite is enabled on a server but not on a client, allowing man-in-the-middle attackers to conduct cipher-downgrade attacks. This is achieved by rewriting a ClientHello with DHE replaced by DHE EXPORT and then rewriting a ServerHello with DHE EXPORT replaced by DHE, also known as the "Logjam" issue. An attacker could exploit this vulnerability using man-in-the-middle techniques to force a downgrade to 512-bit export-grade cipher, potentially allowing them to recover the session key and modify the contents of the traffic.
Recommendations For TLS protocol versions 1.2 and earlier, consider disabling the DHE EXPORT ciphersuite to prevent exploitation until a patch is available. As a temporary workaround, restrict access to servers that have DHE EXPORT enabled to minimize the risk of exploitation. Avoid using the DHE EXPORT ciphersuite in the ClientHello and ServerHello messages until the issue is resolved.

Exploit

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1574
ALT-PU-2015-1669
ALT-PU-2015-1863
BDU:2015-11042
CESA-2015_1072
CESA-2015_1185
CESA-2015_1228
CESA-2015_1229
CESA-2015_1526
CVE-2015-4000
DLA-247-1
DLA-303-1
DLA-507-1
DSA-3287-1
DSA-3300-1
DSA-3316-1
DSA-3324-1
DSA-3339-1
DSA-3688-1
HPSBUX03388
HPSBUX03512
MGASA-2015-0246
MGASA-2015-0260
MGASA-2015-0268
MGASA-2015-0277
MGASA-2015-0280
OPENSUSE-SU-2015_1139-1
OPENSUSE-SU-2015_1216-1
OPENSUSE-SU-2015_1229-1
OPENSUSE-SU-2015_1277-1
OPENSUSE-SU-2015_1288-1
OPENSUSE-SU-2015_1289-1
OPENSUSE-SU-2016_0226-1
OPENSUSE-SU-2016_0255-1
OPENSUSE-SU-2016_0261-1
OPENSUSE-SU-2023_4506-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:10197-1
OPENSUSE-SU-2024:10230-1
OPENSUSE-SU-2024:10268-1
OPENSUSE-SU-2024:10309-1
OPENSUSE-SU-2024:10371-1
OPENSUSE-SU-2024:10451-1
OPENSUSE-SU-2024:10534-1
OPENSUSE-SU-2024:14572-1
RHSA-2015:1072
RHSA-2015:1185
RHSA-2015:1197
RHSA-2015:1228
RHSA-2015:1229
RHSA-2015:1230
RHSA-2015:1241
RHSA-2015:1242
RHSA-2015:1243
RHSA-2015:1485
RHSA-2015:1486
RHSA-2015:1488
RHSA-2015:1526
RHSA-2015:1544
RHSA-2015:1604
RHSA-2015_1072
RHSA-2015_1185
RHSA-2015_1197
RHSA-2015_1228
RHSA-2015_1229
RHSA-2015_1230
RHSA-2015_1241
RHSA-2015_1242
RHSA-2015_1243
RHSA-2015_1485
RHSA-2015_1486
RHSA-2015_1526
RHSA-2015_1544
SUSE-FU-2022:0445-1
SUSE-RU-2015:0769-1
SUSE-SU-2015:0182-2
SUSE-SU-2015:0543-1
SUSE-SU-2015:0545-1
SUSE-SU-2015:0545-2
SUSE-SU-2015:0546-1
SUSE-SU-2015:0547-1
SUSE-SU-2015:0578-1
SUSE-SU-2015:0620-1
SUSE-SU-2015:0946-1
SUSE-SU-2015:1143-1
SUSE-SU-2015:1150-1
SUSE-SU-2015:1177-1
SUSE-SU-2015:1177-2
SUSE-SU-2015:1182-1
SUSE-SU-2015:1182-2
SUSE-SU-2015:1183-1
SUSE-SU-2015:1183-2
SUSE-SU-2015:1184-1
SUSE-SU-2015:1184-2
SUSE-SU-2015:1185-1
SUSE-SU-2015:1268-1
SUSE-SU-2015:1268-2
SUSE-SU-2015:1269-1
SUSE-SU-2015:1319-1
SUSE-SU-2015:1320-1
SUSE-SU-2015:1329-1
SUSE-SU-2015:1331-1
SUSE-SU-2015:1345-1
SUSE-SU-2015:1375-1
SUSE-SU-2015:1449-1
SUSE-SU-2015:1482-1
SUSE-SU-2015:1509-1
SUSE-SU-2015:1526-1
SUSE-SU-2015:1544-1
SUSE-SU-2015:1581-1
SUSE-SU-2015:1663-1
SUSE-SU-2015:1695-1
SUSE-SU-2015:1840-1
SUSE-SU-2015:1851-1
SUSE-SU-2015_1177-1
SUSE-SU-2015_1177-2
SUSE-SU-2015_1482-1
SUSE-SU-2015_1526-1
SUSE-SU-2015_1544-1
SUSE-SU-2015_1547-1
SUSE-SU-2015_1547-2
SUSE-SU-2015_1581-1
SUSE-SU-2015_1695-1
SUSE-SU-2015_1840-1
SUSE-SU-2016:0224-1
SUSE-SU-2016:0262-1
SUSE-SU-2016:0344-1
SUSE-SU-2016:1618-1
SUSE-SU-2016:2209-1
SUSE-SU-2016:2385-1
SUSE-SU-2016_0224-1
SUSE-SU-2016_0344-1
SUSE-SU-2016_1618-1
SUSE-SU-2016_2209-1
SUSE-SU-2016_2385-1
SUSE-SU-2018:1768-1
SUSE-SU-2018_1768-1
SUSE-SU-2023:0586-1
SUSE-SU-2023:4506-1
SUSE-SU-2023:4507-1
SUSE-SU-2023_0586-1
SUSE-SU-2023_4506-1
SUSE-SU-2023_4507-1
SUSE-SU-403
USN-2624-1
USN-2625-1
USN-2639-1
USN-2656-1
USN-2656-2
USN-2673-1
USN-2696-1
USN-2706-1

Affected Products

Alt Linux
Centos
Hpe Ilo
Hp-Ux
Ibm Aix
Java Platform
Jira
Junos
Openssl
Red Hat
Suse
Tls
Ubuntu