CVE-2015-4000

Advisory lineage Upstream: 0 Downstream: 76
Modified
Published: 21 May 2015, 00:00
Last modified:27 May 2026, 16:22

Vulnerability Summary

Overall Risk (default)
medium
46/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
92.35% CRITICAL
92% probability -1.55%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

21 May 2015, 00:00
Published
Vulnerability first disclosed
27 May 2026, 16:22
Last Modified
Vulnerability information updated

Description

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CVSS Metrics

  • v3.1LOWScore: 3.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
  • v3.0LOWScore: 3.7CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 92.35% Percentile: 100%

Techniques & Countermeasures

  • CWE-310Cryptographic Issues

    Weaknesses in this category are related to the design and implementation of data confidentiality and integrity. Frequently these deal with the use of encoding techniques, encryption libraries, and hashing algorithms. The weaknesses in this category could lead to a degradation of the quality data if they are not addressed.

  • CWE-295Improper Certificate Validation

    The product does not validate, or incorrectly validates, a certificate.

Affected Systems

  • appleiphone_os

    ≤ 8.3

  • applemac_os_x

    ≤ 10.10.3

  • applesafari

    na

  • canonicalubuntu_linux

    12.04 | 14.04 | 14.10 | 15.04

  • debiandebian_linux

    7.0 | 8.0

  • googlechrome

    na

  • hphp-ux

    b.11.31

  • ibmcontent_manager

    8.5

  • UnknownInternet Explorer

    na

  • mozillafirefox

    na | 38.1.0 | 39.0

  • mozillafirefox_esr

    31.8

  • mozillafirefox_os

    2.2

  • mozillanetwork_security_services

    3.19

  • mozillaseamonkey

    2.35

  • mozillathunderbird

    31.8 | 38.1

  • UnknownOpenSSL

    ≥ 1.0.1, ≤ 1.0.1m | ≥ 1.0.2, ≤ 1.0.2a | ≤ 1.0.1m

  • operaopera_browser

    na

  • oraclejdk

    1.6.0:update95 | 1.7.0:update75 | 1.7.0:update80 | 1.8.0:update_33 | 1.8.0:update45

  • oraclejre

    1.6.0:update_95 | 1.7.0:update_75 | 1.7.0:update_80 | 1.8.0:update_33 | 1.8.0:update_45

  • oraclejrockit

    r28.3.6

  • oraclesparc-opl_service_processor

    ≤ 1121

  • suselinux_enterprise_desktop

    12

  • suselinux_enterprise_server

    11.0:sp4

  • suselinux_enterprise_software_development_kit

    12

  • susesuse_linux_enterprise_server

    12

References (217)