← Back to CVE List
Vulnerability Intelligence Report

CVE-2015-3197

ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.

No Active Exploit Signals
CVSS Base Score
5.9
MEDIUM
EPSS Probability:10.73%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
oracle tuxedo 12.1.1.0
oracle exalogic_infrastructure 1.0, 2.0
oracle peoplesoft_enterprise_peopletools 8.53, 8.54, 8.55
openssl openssl 1.0.1, 1.0.1a, 1.0.1b, 1.0.1c, 1.0.1d, 1.0.1e, 1.0.1f, 1.0.1g, 1.0.1h, 1.0.1i, 1.0.1j, 1.0.1k, 1.0.1l, 1.0.1m, 1.0.1n, 1.0.1o, 1.0.1p, 1.0.1q, 1.0.2, 1.0.2a, 1.0.2b, 1.0.2c, 1.0.2d, 1.0.2e
oracle oss_support_tools 8.11.16.3.8
oracle vm_virtualbox 5.0.16

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
10.731%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2015-04-10T00:00:00
Published2016-02-15T00:00:00
Patch Date2016-01-28
Last Updated2024-08-06T05:39:31

LINK COPIED TO CLIPBOARD