Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2003-0131

The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.232
EPSS Ranking 95.6%
CVSS Severity
CVSS v2 Score 7.5
References
Products affected by CVE-2003-0131
  • Openssl » Openssl » Version: 0.9.6
    cpe:2.3:a:openssl:openssl:0.9.6
  • Openssl » Openssl » Version: 0.9.6a
    cpe:2.3:a:openssl:openssl:0.9.6a
  • Openssl » Openssl » Version: 0.9.6b
    cpe:2.3:a:openssl:openssl:0.9.6b
  • Openssl » Openssl » Version: 0.9.6c
    cpe:2.3:a:openssl:openssl:0.9.6c
  • Openssl » Openssl » Version: 0.9.6d
    cpe:2.3:a:openssl:openssl:0.9.6d
  • Openssl » Openssl » Version: 0.9.6e
    cpe:2.3:a:openssl:openssl:0.9.6e
  • Openssl » Openssl » Version: 0.9.6g
    cpe:2.3:a:openssl:openssl:0.9.6g
  • Openssl » Openssl » Version: 0.9.6h
    cpe:2.3:a:openssl:openssl:0.9.6h
  • Openssl » Openssl » Version: 0.9.6i
    cpe:2.3:a:openssl:openssl:0.9.6i
  • Openssl » Openssl » Version: 0.9.7
    cpe:2.3:a:openssl:openssl:0.9.7
  • Openssl » Openssl » Version: 0.9.7a
    cpe:2.3:a:openssl:openssl:0.9.7a


Contact Us

Shodan ® - All rights reserved