CVE-2015-0204

Description

The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct RSA-to-EXPORT_RSA downgrade attacks and facilitate brute-force decryption by offering a weak ephemeral RSA key in a noncompliant role, related to the FREAK issue. NOTE: the scope of this CVE is only client code based on OpenSSL, not EXPORT_RSA issues associated with servers or other TLS implementations.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
92.433

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities fixed in OpenSSL (x64) 0.9.8zdWindows
Multiple vulnerabilities fixed in OpenSSL (x64) 1.0.0pWindows
Multiple vulnerabilities fixed in OpenSSL (x64) 1.0.1kWindows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.2.3Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.1.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 8.5Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 8.5.1Windows
SUSE-SU-2015:2166-1(SUSE Linux Enterprise Server 11-SP3 ) java-1_6_0-ibm-1.6.0_sr16.15-46.1.x86_64.rpmLinux
SUSE-SU-2015:2166-1(SUSE Linux Enterprise Server 11-SP3 ) java-1_6_0-ibm-alsa-1.6.0_sr16.15-46.1.i586.rpmLinux
SUSE-SU-2015:2166-1(SUSE Linux Enterprise Server 11-SP3 ) java-1_6_0-ibm-fonts-1.6.0_sr16.15-46.1.x86_64.rpmLinux
SUSE-SU-2015:2166-1(SUSE Linux Enterprise Server 11-SP3 ) java-1_6_0-ibm-jdbc-1.6.0_sr16.15-46.1.x86_64.rpmLinux
SUSE-SU-2015:2166-1(SUSE Linux Enterprise Server 11-SP3 ) java-1_6_0-ibm-plugin-1.6.0_sr16.15-46.1.x86_64.rpmLinux
SUSE-SU-2015:2216-1(SUSE Linux Enterprise Server 11-SP3 ) java-1_7_0-ibm-1.7.0_sr9.20-42.1.x86_64.rpmLinux
SUSE-SU-2015:2216-1(SUSE Linux Enterprise Server 11-SP3 ) java-1_7_0-ibm-alsa-1.7.0_sr9.20-42.1.x86_64.rpmLinux
SUSE-SU-2015:2216-1(SUSE Linux Enterprise Server 11-SP3 ) java-1_7_0-ibm-jdbc-1.7.0_sr9.20-42.1.x86_64.rpmLinux
SUSE-SU-2015:2216-1(SUSE Linux Enterprise Server 11-SP3 ) java-1_7_0-ibm-plugin-1.7.0_sr9.20-42.1.x86_64.rpmLinux
Multiple Vulnerabilities in OpenSSL (January 2015) Affecting Cisco Products For Cisco IOSNCM
Multiple Vulnerabilities in OpenSSL (January 2015) Affecting Cisco Products For Cisco IOS XE SoftwareNCM
Multiple Vulnerabilities in OpenSSL (January 2015) Affecting Cisco Products For Cisco NX-OS SoftwareNCM
CVE-2015-0204NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706090Security Update for Cisco IOS Amsterdam-17.2.1r
PATCH-1706107Security Update for Cisco IOS XE Software 5.2(1)SV5(1.3a)
PATCH-1706149Security Update for Cisco NX-OS Software 4.1(3a)UCSM

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234