Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3471
HistoryFeb 07, 2017 - 12:57 a.m.

Man-in-the-Middle (MitM)

2017-02-0700:57:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22

0.007 Low

EPSS

Percentile

80.6%

OpenSSL is vulnerable to man in the middle (MitM) attacks. These attacks are possible through the ssl23_get_client_hello function in s23_srvr.c. It can be triggered by a ClientHello message fragment which forces OpenSSL to negotiate using the TLS 1.0 protocol insteadl of a higher, more secure version.

References