CVE-2005-2946

Description

The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.19

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in OpenSSL 0.9.7gWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.1cWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.2bWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.3Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.3aWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.4Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.5Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.5aWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6aWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6bWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6cWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6dWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6eWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6fWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6gWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6hWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6iWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6jWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6kWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6lWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6mWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7aWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7bWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7cWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7dWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7eWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7fWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7gWindows
Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2005-2946)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234