Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3454
HistoryFeb 06, 2017 - 6:25 a.m.

ECDHE-to-ECDH Downgrade Attacks

2017-02-0606:25:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

0.006 Low

EPSS

Percentile

77.9%

OpenSSL is vulnerable to ECDHE-to-ECDH downgrade attacks. This is due to a flaw in ssl3_get_key_exchange which allows attackers to trigger a loss of forward secrecy to omitting the ServerKeyExchange message.

References