Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3551
HistoryFeb 10, 2017 - 2:13 a.m.

Cryptographic Protection Bypass

2017-02-1002:13:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

EPSS

0.006

Percentile

78.7%

OpenSSL is vulnerable to cryptographic protection bypass. This is possible because it doesn’t ensure that the PRNG is seeded before proceeding with a handshake. The flaw allows attackers to defeat the cryptographic protection mechanisms by sniffing the network then performing a brute-force attack.

References