Lucene search

K
cve[email protected]CVE-2015-3230
HistoryOct 29, 2015 - 8:59 p.m.

CVE-2015-3230

2015-10-2920:59:00
CWE-254
web.nvd.nist.gov
30
cve-2015-3230
389 directory server
fedora directory server
nvd
security vulnerability

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.8 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

81.1%

389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows remote attackers to have unspecified impact by requesting to use a disabled cipher.

Affected configurations

NVD
Node
fedoraproject389_directory_serverRange1.3.3.10

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.8 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

81.1%