CVE-2014-3511 : Detail

CVE-2014-3511

0.76%V3
Network
2014-08-13
21h00 +00:00
2017-11-14
09h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 1.0.1 before 1.0.1i allows man-in-the-middle attackers to force the use of TLS 1.0 by triggering ClientHello message fragmentation in communication between a client and server that both support later TLS versions, related to a "protocol downgrade" issue.

CVE Informations

Related Weaknesses

CWE-ID Weakness Name Source
CWE Other No informations.

Metrics

Metrics Score Severity CVSS Vector Source
V2 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N [email protected]

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Products Mentioned

Configuraton 0

Openssl>>Openssl >> Version 1.0.0

Openssl>>Openssl >> Version 1.0.0

Openssl>>Openssl >> Version 1.0.0

Openssl>>Openssl >> Version 1.0.0

Openssl>>Openssl >> Version 1.0.0

Openssl>>Openssl >> Version 1.0.0

Openssl>>Openssl >> Version 1.0.0a

Openssl>>Openssl >> Version 1.0.0b

Openssl>>Openssl >> Version 1.0.0c

Openssl>>Openssl >> Version 1.0.0d

Openssl>>Openssl >> Version 1.0.0e

Openssl>>Openssl >> Version 1.0.0f

Openssl>>Openssl >> Version 1.0.0g

Openssl>>Openssl >> Version 1.0.0h

Openssl>>Openssl >> Version 1.0.0i

Openssl>>Openssl >> Version 1.0.0j

Openssl>>Openssl >> Version 1.0.0k

Openssl>>Openssl >> Version 1.0.0l

Openssl>>Openssl >> Version 1.0.0m

Openssl>>Openssl >> Version 1.0.1

Openssl>>Openssl >> Version 1.0.1

Openssl>>Openssl >> Version 1.0.1

Openssl>>Openssl >> Version 1.0.1

Openssl>>Openssl >> Version 1.0.1a

Openssl>>Openssl >> Version 1.0.1b

Openssl>>Openssl >> Version 1.0.1c

Openssl>>Openssl >> Version 1.0.1d

Openssl>>Openssl >> Version 1.0.1e

Openssl>>Openssl >> Version 1.0.1f

Openssl>>Openssl >> Version 1.0.1g

Openssl>>Openssl >> Version 1.0.1h

References

http://secunia.com/advisories/60221
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/61184
Tags : third-party-advisory, x_refsource_SECUNIA
http://marc.info/?l=bugtraq&m=142660345230545&w=2
Tags : vendor-advisory, x_refsource_HP
http://secunia.com/advisories/60022
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/61017
Tags : third-party-advisory, x_refsource_SECUNIA
http://rhn.redhat.com/errata/RHSA-2015-0197.html
Tags : vendor-advisory, x_refsource_REDHAT
http://secunia.com/advisories/60377
Tags : third-party-advisory, x_refsource_SECUNIA
http://marc.info/?l=bugtraq&m=142350350616251&w=2
Tags : vendor-advisory, x_refsource_HP
http://secunia.com/advisories/59887
Tags : third-party-advisory, x_refsource_SECUNIA
http://marc.info/?l=bugtraq&m=142791032306609&w=2
Tags : vendor-advisory, x_refsource_HP
http://secunia.com/advisories/60890
Tags : third-party-advisory, x_refsource_SECUNIA
http://security.gentoo.org/glsa/glsa-201412-39.xml
Tags : vendor-advisory, x_refsource_GENTOO
http://marc.info/?l=bugtraq&m=142660345230545&w=2
Tags : vendor-advisory, x_refsource_HP
http://marc.info/?l=bugtraq&m=142495837901899&w=2
Tags : vendor-advisory, x_refsource_HP
http://secunia.com/advisories/60803
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/59700
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.securitytracker.com/id/1030693
Tags : vdb-entry, x_refsource_SECTRACK
http://www.splunk.com/view/SP-CAAANHS
Tags : x_refsource_CONFIRM
http://secunia.com/advisories/60917
Tags : third-party-advisory, x_refsource_SECUNIA
http://marc.info/?l=bugtraq&m=142350350616251&w=2
Tags : vendor-advisory, x_refsource_HP
http://secunia.com/advisories/60493
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/59710
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/60921
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.securityfocus.com/bid/69079
Tags : vdb-entry, x_refsource_BID
http://secunia.com/advisories/61043
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/60810
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/61100
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/61775
Tags : third-party-advisory, x_refsource_SECUNIA
http://marc.info/?l=bugtraq&m=142495837901899&w=2
Tags : vendor-advisory, x_refsource_HP
http://www.debian.org/security/2014/dsa-2998
Tags : vendor-advisory, x_refsource_DEBIAN
http://marc.info/?l=bugtraq&m=143290437727362&w=2
Tags : vendor-advisory, x_refsource_HP
http://secunia.com/advisories/61959
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/59756
Tags : third-party-advisory, x_refsource_SECUNIA
http://marc.info/?l=bugtraq&m=142624590206005&w=2
Tags : vendor-advisory, x_refsource_HP
http://marc.info/?l=bugtraq&m=143290522027658&w=2
Tags : vendor-advisory, x_refsource_HP
http://rhn.redhat.com/errata/RHSA-2015-0126.html
Tags : vendor-advisory, x_refsource_REDHAT
http://secunia.com/advisories/58962
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/60938
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/60684
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/61139
Tags : third-party-advisory, x_refsource_SECUNIA