Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11685
HistoryJan 15, 2019 - 9:06 a.m.

Man-in-the-Middle (MitM)

2019-01-1509:06:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.974 High

EPSS

Percentile

99.9%

openssl is vulnerable to man-in-the-middle (MitM) attacks. The vulnerability exists as the TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the “Logjam” issue.

References