← All CVEs

CVE-2015-3197

medium · 5.9

ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.

5.9
CVSS
10.7%
EPSS (exploit prob.)
96th
EPSS percentile
2016-02-15
Published

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-200CWE-310

Affected products

VendorProductAffected versions
oracletuxedo12.1.1.0
oracleexalogic_infrastructure1.0
oracleexalogic_infrastructure2.0
oraclepeoplesoft_enterprise_peopletools8.53
oraclepeoplesoft_enterprise_peopletools8.54
oraclepeoplesoft_enterprise_peopletools8.55
opensslopenssl1.0.1
opensslopenssl1.0.1
opensslopenssl1.0.1
opensslopenssl1.0.1
opensslopenssl1.0.1a
opensslopenssl1.0.1b
opensslopenssl1.0.1c
opensslopenssl1.0.1d
opensslopenssl1.0.1e
opensslopenssl1.0.1f
opensslopenssl1.0.1g
opensslopenssl1.0.1h
opensslopenssl1.0.1i
opensslopenssl1.0.1j
opensslopenssl1.0.1k
opensslopenssl1.0.1l
opensslopenssl1.0.1m
opensslopenssl1.0.1n
opensslopenssl1.0.1o
opensslopenssl1.0.1p
opensslopenssl1.0.1q
opensslopenssl1.0.2
opensslopenssl1.0.2
opensslopenssl1.0.2
opensslopenssl1.0.2
opensslopenssl1.0.2a
opensslopenssl1.0.2b
opensslopenssl1.0.2c
opensslopenssl1.0.2d
opensslopenssl1.0.2e
oracleoss_support_tools8.11.16.3.8
oraclevm_virtualbox5.0.16

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-3197