Vulnerability CVE-2011-5095


Published: 2012-06-20

Description:
The Diffie-Hellman key-exchange implementation in OpenSSL 0.9.8, when FIPS mode is enabled, does not properly validate a public parameter, which makes it easier for man-in-the-middle attackers to obtain the shared secret key by modifying network traffic, a related issue to CVE-2011-1923.

CVSS2 => (AV:N/AC:H/Au:N/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
4.9/10
4.9/10
Exploit range
Attack complexity
Authentication
Remote
High
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None
Affected software
Openssl -> Openssl 

 References:
https://discussions.nessus.org/thread/3381
http://www.nessus.org/plugins/index.php?view=single&id=53360
http://www.cl.cam.ac.uk/~rja14/Papers/psandqs.pdf

Copyright 2024, cxsecurity.com

 

Back to Top