CVE-2015-3197

Description

ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
21.948

Associated Vulnerability

VulnerabilityOS Platform
Update VM VirtualBox 5.0.16 to latest versionWindows
Vulnerabilities CVE-2015-3197 are fixed in OpenSSL (x64) 1.0.1rWindows
Vulnerabilities CVE-2016-0701,CVE-2015-3197 are fixed in OpenSSL (x64) 1.0.2fWindows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.54Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.55Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.53Windows
Multiple vulnerabilities are affected in Oracle Primavera P6 Enterprise Project Portfolio Management 8.3Windows
Multiple vulnerabilities are affected in Oracle Primavera P6 Enterprise Project Portfolio Management 8.4Windows
Multiple vulnerabilities are affected in Oracle Primavera P6 Enterprise Project Portfolio Management 15.1Windows
Multiple vulnerabilities are affected in Oracle Primavera P6 Enterprise Project Portfolio Management 15.2Windows
Multiple Vulnerabilities are affected in Oracle Corporation PeopleSoft Enterprise PeopleTools 8.53Windows
Multiple Vulnerabilities are affected in Oracle Corporation PeopleSoft Enterprise PeopleTools 8.54Windows
Multiple Vulnerabilities are affected in Oracle Corporation PeopleSoft Enterprise PeopleTools 8.55Windows
SUSE-SU-2016:0624-1(SUSE Linux Enterprise Desktop 11-SP4 ) libopenssl0_9_8-0.9.8j-0.89.1.x86_64.rpmLinux
SUSE-SU-2016:0624-1(SUSE Linux Enterprise Desktop 11-SP4 ) libopenssl0_9_8-32bit-0.9.8j-0.89.1.x86_64.rpmLinux
SUSE-SU-2016:0624-1(SUSE Linux Enterprise Desktop 11-SP4 ) openssl-0.9.8j-0.89.1.x86_64.rpmLinux
SUSE-SU-2016:0631-1(SUSE Linux Enterprise Desktop 11-SP4 ) compat-openssl097g-0.9.7g-146.22.41.1.x86_64.rpmLinux
SUSE-SU-2016:0631-1(SUSE Linux Enterprise Desktop 11-SP4 ) compat-openssl097g-32bit-0.9.7g-146.22.41.1.x86_64.rpmLinux
SUSE-SU-2016:0678-1(SUSE Linux Enterprise Desktop 12-SP1 ) sled-admin_en-pdf-12.1-7.2.noarch.rpmLinux
SUSE-SU-2016:0678-1(SUSE Linux Enterprise Desktop 12-SP1 ) sled-deployment_en-pdf-12.1-7.2.noarch.rpmLinux
SUSE-SU-2016:0678-1(SUSE Linux Enterprise Desktop 12-SP1 ) sled-gnomeuser_en-pdf-12.1-7.2.noarch.rpmLinux
SUSE-SU-2016:0678-1(SUSE Linux Enterprise Desktop 12-SP1 ) sled-installquick_en-pdf-12.1-7.2.noarch.rpmLinux
SUSE-SU-2016:0678-1(SUSE Linux Enterprise Desktop 12-SP1 ) sled-manuals_en-12.1-7.2.noarch.rpmLinux
SUSE-SU-2016:0678-1(SUSE Linux Enterprise Desktop 12-SP1 ) sled-security_en-pdf-12.1-7.2.noarch.rpmLinux
SUSE-SU-2016:0678-1(SUSE Linux Enterprise Desktop 12-SP1 ) sled-tuning_en-pdf-12.1-7.2.noarch.rpmLinux
Openssl098e update (ELSA-2016-0372) openssl098e-0.9.8e-20.0.1.el6_7.1.x86_64.rpmLinux
Openssl098e update (ELSA-2016-0372) openssl098e-0.9.8e-20.0.1.el6_7.1.i686.rpmLinux
Openssl098e update (ELSA-2016-0372) openssl098e-0.9.8e-29.el7_2.3.x86_64.rpmLinux
Openssl098e update (ELSA-2016-0372) openssl098e-0.9.8e-29.el7_2.3.i686.rpmLinux
(RHSA-2016:0372)Important: security update openssl098e-0.9.8e-29.el7_2.3.i686.rpmLinux
(RHSA-2016:0372)Important: security update openssl098e-0.9.8e-29.el7_2.3.x86_64.rpmLinux
(RHSA-2016:0372)Important: security update openssl098e-debuginfo-0.9.8e-29.el7_2.3.i686.rpmLinux
(RHSA-2016:0372)Important: security update openssl098e-debuginfo-0.9.8e-29.el7_2.3.x86_64.rpmLinux
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco Emergency ResponderNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco Jabber for WindowsNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco MediaSenseNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco Mobility Services EngineNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco Prime OpticalNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco Prime Performance ManagerNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco Unified Contact Center EnterpriseNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco Unified Intelligence CenterNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco Unity ConnectionNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco Unity ExpressNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco IronPort Encryption Appliance SoftwareNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco IronPort Email Security Appliance SoftwareNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco UCS DirectorNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco Nexus 7000 Series SwitchesNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For CiscoPro Workgroup EtherSwitch SoftwareNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco Unified Computing SystemNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco Prime CollaborationNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco Unified Communications LicensingNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco TelePresence Video Communication Server SoftwareNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco ConductorNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco ONS 15454 Series Multiservice Provisioning PlatformsNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco IPS 4200 Series SensorsNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco AS Series Media Processor SoftwareNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco TelePresence Administration SoftwareNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco Unified Attendant ConsolesNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco Unified Communications Manager (CallManager)NCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco SIP IP Phone SoftwareNCM
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products For Cisco IP Phone 8800 SeriesNCM
CVE-2015-3197NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-342239Oracle VM VirtualBox (7.1.4)
PATCH-1706049Security Update for Cisco Emergency Responder 12.0(0.98000.50)
PATCH-1705811Security Update for Cisco Jabber for Windows 11.6(1.38147)
PATCH-1705879Security Update for Cisco MediaSense 11.5(1.10000.6)
PATCH-1705808Security Update for Cisco Mobility Services Engine 8.0(130.12)
PATCH-1706040Security Update for Cisco Prime Optical 10.6(1)
PATCH-1706037Security Update for Cisco Prime Performance Manager 1.7(0.1703)
PATCH-1705943Security Update for Cisco Unified Contact Center Enterprise 11.6(1)SR0(0)
PATCH-1705886Security Update for Cisco Unified Intelligence Center 11.5(0.98000.126)
PATCH-1706048Security Update for Cisco Unity Connection 12.0(0.97000.184)
PATCH-1703070Security Update for Cisco Unity Express 6.2.1
PATCH-1706003Security Update for Cisco IronPort Email Security Appliance Software 9.7.2-131
PATCH-1705947Security Update for Cisco UCS Director 6.0(1.0)
PATCH-1705790Security Update for Cisco Nexus 7000 Series Switches 7.3(2)D1(1)
PATCH-1706035Security Update for CiscoPro Workgroup EtherSwitch Software 6.0(2)A8(4)
PATCH-1706036Security Update for Cisco Unified Computing System 3.2(1d)
PATCH-1705997Security Update for Cisco Prime Collaboration 11.0(0.815)
PATCH-1706042Security Update for Cisco Unified Communications Licensing 11.5(1.12001.2)
PATCH-1706044Security Update for Cisco TelePresence Video Communication Server Software X8.9.2
PATCH-1705867Security Update for Cisco Conductor 3.600
PATCH-1705963Security Update for Cisco ONS 15454 Series Multiservice Provisioning Platforms 10.6(2)
PATCH-1705754Security Update for Cisco IPS 4200 Series Sensors 7.3(5)P1
PATCH-1705872Security Update for Cisco AS Series Media Processor Software CAL9.7
PATCH-1705874Security Update for Cisco TelePresence Administration Software 6.1.13_3
PATCH-1706047Security Update for Cisco Unified Attendant Consoles 11.0(2)
PATCH-1706016Security Update for Cisco Unified Communications Manager (CallManager) CUP.11.5(1.12900.25)
PATCH-1705918Security Update for Cisco SIP IP Phone Software 11.7(1)MN19
PATCH-1705974Security Update for Cisco IP Phone 8800 Series 11.7(1)SC2

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234