CVE-2005-2969

Advisory lineage Upstream: 0 Downstream: 9
Modified
Published: 18 Oct 2005, 04:00
Last modified:07 Aug 2024, 22:53

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
9.39% LOW
9% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Oct 2005, 04:00
Published
Vulnerability first disclosed
07 Aug 2024, 22:53
Last Modified
Vulnerability information updated

Description

The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 9.39% Percentile: 93%

Affected Systems

  • UnknownOpenSSL

    0.9.7 | 0.9.7a | 0.9.7b | 0.9.7c | 0.9.7d | 0.9.7e | 0.9.7f | 0.9.7g | 0.9.8

References (74)