Lucene search

K
cve[email protected]CVE-2003-0192
HistoryAug 18, 2003 - 4:00 a.m.

CVE-2003-0192

2003-08-1804:00:00
web.nvd.nist.gov
65
cve-2003-0192
apache
mod_ssl
sslciphersuite
vulnerability
nvd

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

9.3 High

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.0%

Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle “certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one,” which could cause Apache to use the weak ciphersuite.

Affected configurations

NVD
Node
apachehttp_serverMatch2.0
OR
apachehttp_serverMatch2.0.28
OR
apachehttp_serverMatch2.0.32
OR
apachehttp_serverMatch2.0.35
OR
apachehttp_serverMatch2.0.36
OR
apachehttp_serverMatch2.0.37
OR
apachehttp_serverMatch2.0.38
OR
apachehttp_serverMatch2.0.39
OR
apachehttp_serverMatch2.0.40
OR
apachehttp_serverMatch2.0.41
OR
apachehttp_serverMatch2.0.42
OR
apachehttp_serverMatch2.0.43
OR
apachehttp_serverMatch2.0.44
OR
apachehttp_serverMatch2.0.45
OR
apachehttp_serverMatch2.0.46

References

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

9.3 High

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.0%