Lucene search

K
cveMitreCVE-2014-9721
HistoryJun 03, 2015 - 8:59 p.m.

CVE-2014-9721

2015-06-0320:59:00
CWE-20
mitre
web.nvd.nist.gov
41
cve
2014
9721
libzmq
downgrade attack
vulnerability
nvd
security
zmtp

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.005

Percentile

75.6%

libzmq before 4.0.6 and 4.1.x before 4.1.1 allows remote attackers to conduct downgrade attacks and bypass ZMTP v3 protocol security mechanisms via a ZMTP v2 or earlier header.

Affected configurations

Nvd
Node
zeromqzeromqRange4.0.5
OR
zeromqzeromqMatch4.1.0rc1
VendorProductVersionCPE
zeromqzeromq*cpe:2.3:a:zeromq:zeromq:*:*:*:*:*:*:*:*
zeromqzeromq4.1.0cpe:2.3:a:zeromq:zeromq:4.1.0:rc1:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.005

Percentile

75.6%