← All CVEs

CVE-2015-4000

low · 3.7

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

3.7
CVSS
99.9%
EPSS (exploit prob.)
100th
EPSS percentile
2015-05-21
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Weaknesses

CWE-310CWE-295

Affected products

VendorProductAffected versions
opensslopenssl>= 1.0.1, <= 1.0.1m
opensslopenssl>= 1.0.2, <= 1.0.2a
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux14.10
canonicalubuntu_linux15.04
opensslopenssl<= 1.0.1m
hphp-uxb.11.31
ibmcontent_manager8.5
oraclejrockitr28.3.6
debiandebian_linux7.0
debiandebian_linux8.0
oraclejdk1.6.0
oraclejdk1.7.0
oraclejdk1.7.0
oraclejdk1.8.0
oraclejdk1.8.0
oraclejre1.6.0
oraclejre1.7.0
oraclejre1.7.0
oraclejre1.8.0
oraclejre1.8.0
suselinux_enterprise_desktop12
suselinux_enterprise_server11.0
suselinux_enterprise_software_development_kit12
susesuse_linux_enterprise_server12
appleiphone_os<= 8.3
applemac_os_x<= 10.10.3
mozillanetwork_security_services3.19
oraclesparc-opl_service_processor<= 1121
applesafariall versions
googlechromeall versions
microsoftinternet_explorerall versions
mozillafirefoxall versions
operaopera_browserall versions
mozillafirefox38.1.0
mozillafirefox39.0
mozillafirefox_esr31.8
mozillaseamonkey2.35
mozillathunderbird31.8

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-4000