CVE-2015-1794

Description

The ssl3_get_key_exchange function in ssl/s3_clnt.c in OpenSSL 1.0.2 before 1.0.2e allows remote servers to cause a denial of service (segmentation fault) via a zero p value in an anonymous Diffie-Hellman (DH) ServerKeyExchange message.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
10.711

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2015-3195,CVE-2015-3194,CVE-2015-3193,CVE-2015-1794 are fixed in OpenSSL (x64) 1.0.2eWindows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2Windows
Secure Socket Layer (SSL) cryptographic library and tools (USN-2624-1) libssl1.0.0_1.0.1f-1ubuntu11.5_i386.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-2624-1) libssl1.0.0_1.0.1f-1ubuntu11.5_amd64.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-2830-1) libssl1.0.0_1.0.2d-0ubuntu1_i386.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-2830-1) libssl1.0.0_1.0.2d-0ubuntu1_amd64.debLinux
Multiple Vulnerabilities in OpenSSL (December 2015) Affecting Cisco Products For Cisco Jabber for MacNCM
Multiple Vulnerabilities in OpenSSL (December 2015) Affecting Cisco Products For Cisco IOS XE SoftwareNCM
Multiple Vulnerabilities in OpenSSL (December 2015) Affecting Cisco Products For Cisco NX-OS SoftwareNCM
CVE-2015-1794NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706107Security Update for Cisco IOS XE Software 5.2(1)SV5(1.3a)
PATCH-1706149Security Update for Cisco NX-OS Software 4.1(3a)UCSM

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234