← Back to CVE List
Vulnerability Intelligence Report

CVE-2009-3555

The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:87.26%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-300 ↗CWE-300 Channel Accessible by Non-Endpoint

Affected Products & Versions

Vendor Product Affected Versions
apache http_server all
gnu gnutls all
mozilla nss all
openssl openssl 1.0
canonical ubuntu_linux 8.04, 8.10, 9.04, 9.10, 10.04, 10.10
debian debian_linux 4.0, 5.0, 6.0, 7.0, 8.0
fedoraproject fedora 11, 12, 13, 14
f5 nginx all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
87.264%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2009-10-05T00:00:00
Published2009-11-09T17:00:00
Patch Date2009-11-04
Last Updated2026-05-27T15:38:56

LINK COPIED TO CLIPBOARD