CVE-2008-7270

Description

OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.

Risk Information

Base Score
9.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
1.096

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in OpenSSL 0.9.8iWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.1cWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.2bWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.3Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.3aWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.4Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.5Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.5aWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6aWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6bWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6cWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6dWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6eWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6fWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6gWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6hWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6iWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6jWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6kWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6lWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.6mWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7aWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7bWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7cWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7dWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7eWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7fWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7gWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7hWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7iWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7jWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7kWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7lWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.7mWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8Windows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8aWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8bWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8cWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8dWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8eWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8fWindows
Multiple Vulnerabilities are affected in OpenSSL 0.9.8gWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)
PATCH-352259OpenSSL (3.6.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234