CVE-2015-4000

Published May 21, 2015

Last updated 18 days ago

Overview

Description
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
Source
cve@mitre.org
NVD status
Modified
Products
openssl, ubuntu_linux, hp-ux, content_manager, jrockit, debian_linux, jdk, jre, linux_enterprise_desktop, linux_enterprise_server, linux_enterprise_software_development_kit, suse_linux_enterprise_server, iphone_os, mac_os_x, network_security_services, sparc-opl_service_processor, safari, chrome, internet_explorer, firefox, opera_browser, firefox_esr, seamonkey, thunderbird, firefox_os

Risk scores

CVSS 3.0

Type
Primary
Base score
3.7
Impact score
1.4
Exploitability score
2.2
Vector string
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Severity
LOW

CVSS 2.0

Type
Primary
Base score
4.3
Impact score
2.9
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:N/I:P/A:N

Weaknesses

nvd@nist.gov
CWE-310

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.