Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3354
HistoryJan 27, 2017 - 8:38 a.m.

DROWN Attack

2017-01-2708:38:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22

0.952 High

EPSS

Percentile

99.4%

OpenSSL is vulnerable to the DROWN attack. The DROWN attack is also known as a Bleichenbacher RSA padding oracle. This vulnerability allows a malicious user to recover a session key from SSL2.0 connections, allowing them to decrypt such connections.

References