Lucene search

K
f5F5F5:K16126
HistorySep 16, 2015 - 12:00 a.m.

K16126 : OpenSSL vulnerability CVE-2014-3572

2015-09-1600:00:00
my.f5.com
73

6.6 Medium

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

77.9%

Security Advisory Description

The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct ECDHE-to-ECDH downgrade attacks and trigger a loss of forward secrecy by omitting the ServerKeyExchange message. (CVE-2014-3572)

Impact

This vulnerability can only be exploited if the HTTPS health monitor that is configured with ECDH cipher suite is monitoring a malicious Secure Socket Layer (SSL) server that is performing the described attack. When exploited, the malicious SSL server can remove the forward secrecy from the cipher suite.