NVD
- Id
- 22706
- Name
- CVE-2015-0204
- Description
- The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct RSA-to-EXPORT_RSA downgrade attacks and facilitate brute-force decryption by offering a weak ephemeral RSA key in a noncompliant role, related to the "FREAK" issue. NOTE: the scope of this CVE is only client code based on OpenSSL, not EXPORT_RSA issues associated with servers or other TLS implementations.
- Reject
- CVSS Version
- 2
- CVSS Score
- 4.3
- Severity
- Medium
- CVSS Base Score
- 4.3
- CVSS Impact Subscore
- 2.9
- CVSS Exploit Subscore
- 8.6
- CVSS Vector
- (AV:N/AC:M/Au:N/C:N/I:P/A:N)
- Pub Date
- 2017-01-19
- Published
- 2015-01-08
- Modified Date
- 2017-01-02
- Seq
- 2015-0204
Related NVD References
Id | NVD Id | NVD No. | Reference | Actions |
---|---|---|---|---|
119936 | 22706 | CVE-2015-0204 | http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10679 | View |
119937 | 22706 | CVE-2015-0204 | APPLE-SA-2015-04-08-2 | View |
119938 | 22706 | CVE-2015-0204 | openSUSE-SU-2015:0130 | View |
119939 | 22706 | CVE-2015-0204 | SUSE-SU-2015:0578 | View |
119940 | 22706 | CVE-2015-0204 | SUSE-SU-2015:0946 | View |
119941 | 22706 | CVE-2015-0204 | SUSE-SU-2015:1085 | View |
119942 | 22706 | CVE-2015-0204 | SUSE-SU-2015:1086 | View |
119943 | 22706 | CVE-2015-0204 | SUSE-SU-2015:1138 | View |
119944 | 22706 | CVE-2015-0204 | SUSE-SU-2015:1161 | View |
119945 | 22706 | CVE-2015-0204 | SUSE-SU-2015:2166 | View |
119946 | 22706 | CVE-2015-0204 | SUSE-SU-2015:2168 | View |
119947 | 22706 | CVE-2015-0204 | SUSE-SU-2015:2182 | View |
119948 | 22706 | CVE-2015-0204 | SUSE-SU-2015:2192 | View |
119949 | 22706 | CVE-2015-0204 | SUSE-SU-2015:2216 | View |
119950 | 22706 | CVE-2015-0204 | SUSE-SU-2016:0113 | View |
119951 | 22706 | CVE-2015-0204 | openSUSE-SU-2016:0640 | View |
119952 | 22706 | CVE-2015-0204 | HPSBUX03162 | View |
119953 | 22706 | CVE-2015-0204 | SSRT101885 | View |
119954 | 22706 | CVE-2015-0204 | SSRT101987 | View |
119955 | 22706 | CVE-2015-0204 | HPSBHF03289 | View |
119956 | 22706 | CVE-2015-0204 | HPSBOV03318 | View |
119957 | 22706 | CVE-2015-0204 | SSRT102000 | View |
119958 | 22706 | CVE-2015-0204 | HPSBMU03380 | View |
119959 | 22706 | CVE-2015-0204 | HPSBMU03345 | View |
119960 | 22706 | CVE-2015-0204 | HPSBMU03409 | View |
119961 | 22706 | CVE-2015-0204 | HPSBMU03396 | View |
119962 | 22706 | CVE-2015-0204 | HPSBMU03413 | View |
119963 | 22706 | CVE-2015-0204 | HPSBMU03397 | View |
119964 | 22706 | CVE-2015-0204 | RHSA-2015:0066 | View |
119965 | 22706 | CVE-2015-0204 | RHSA-2015:0800 | View |
119966 | 22706 | CVE-2015-0204 | RHSA-2015:0849 | View |
119967 | 22706 | CVE-2015-0204 | RHSA-2016:1650 | View |
119968 | 22706 | CVE-2015-0204 | http://support.novell.com/security/cve/CVE-2015-0204.html | View |
119969 | 22706 | CVE-2015-0204 | 20150310 Multiple Vulnerabilities in OpenSSL (January 2015) Affecting Cisco Products | View |
119970 | 22706 | CVE-2015-0204 | http://www-01.ibm.com/support/docview.wss?uid=swg21883640 | View |
119971 | 22706 | CVE-2015-0204 | http://www-304.ibm.com/support/docview.wss?uid=swg21960769 | View |
119972 | 22706 | CVE-2015-0204 | DSA-3125 | View |
119973 | 22706 | CVE-2015-0204 | MDVSA-2015:019 | View |
119974 | 22706 | CVE-2015-0204 | MDVSA-2015:062 | View |
119975 | 22706 | CVE-2015-0204 | MDVSA-2015:063 | View |
119976 | 22706 | CVE-2015-0204 | http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html | View |
119977 | 22706 | CVE-2015-0204 | http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html | View |
119978 | 22706 | CVE-2015-0204 | http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html | View |
119979 | 22706 | CVE-2015-0204 | http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html | View |
119980 | 22706 | CVE-2015-0204 | http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html | View |
119981 | 22706 | CVE-2015-0204 | http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html | View |
119982 | 22706 | CVE-2015-0204 | http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html | View |
119983 | 22706 | CVE-2015-0204 | 71936 | View |
119984 | 22706 | CVE-2015-0204 | 91787 | View |
119985 | 22706 | CVE-2015-0204 | 1033378 | View |
119986 | 22706 | CVE-2015-0204 | openssl-cve20150204-weak-security(99707) | View |
119987 | 22706 | CVE-2015-0204 | https://bto.bluecoat.com/security-advisory/sa88 | View |
119988 | 22706 | CVE-2015-0204 | https://bto.bluecoat.com/security-advisory/sa91 | View |
119989 | 22706 | CVE-2015-0204 | https://freakattack.com/ | View |
119990 | 22706 | CVE-2015-0204 | https://github.com/openssl/openssl/commit/ce325c60c74b0fa784f5872404b722e120e5cab0 | View |
119991 | 22706 | CVE-2015-0204 | https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773241 | View |
119992 | 22706 | CVE-2015-0204 | https://kc.mcafee.com/corporate/index?page=content&id=SB10102 | View |
119993 | 22706 | CVE-2015-0204 | https://kc.mcafee.com/corporate/index?page=content&id=SB10108 | View |
119994 | 22706 | CVE-2015-0204 | https://kc.mcafee.com/corporate/index?page=content&id=SB10110 | View |
119995 | 22706 | CVE-2015-0204 | GLSA-201503-11 | View |
119996 | 22706 | CVE-2015-0204 | https://support.apple.com/HT204659 | View |
119997 | 22706 | CVE-2015-0204 | https://www.openssl.org/news/secadv_20150108.txt | View |
119998 | 22706 | CVE-2015-0204 | https://www.openssl.org/news/secadv_20150319.txt | View |
Related JVN
Id | Name | Title | Summary | Cveinfo Name | Cveinfo Id | Nvdinfo Name | Nvdinfo Id | Cvssv2 | Cvssv3 | Jvnurl | Published Date | Last Updated Date | Actions |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
5689 | JVNDB-2015-001009 | OpenSSL の s3_clnt.c の ssl3_get_key_exchange 関数における RSA-to-EXPORT_RSA ダウングレード攻撃を実行される脆弱性 | OpenSSL の s3_clnt.c の ssl3_get_key_exchange 関数には、RSA-to-EXPORT_RSA ダウングレード攻撃を実行される、および総当たり (brute-force) の復号を容易にされる脆弱性が存在します。 | CVE-2015-0204 | 77415 | CVE-2015-0204 | 22706 | 4.3 | http://jvndb.jvn.jp/ja/contents/2015/JVNDB-2015-001009.html | 2015-01-08 | 2016-11-09 | View |