Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2005-2969

The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.102
EPSS Ranking 92.9%
CVSS Severity
CVSS v2 Score 5.0
References
Products affected by CVE-2005-2969
  • Openssl » Openssl » Version: 0.9.7
    cpe:2.3:a:openssl:openssl:0.9.7
  • Openssl » Openssl » Version: 0.9.7a
    cpe:2.3:a:openssl:openssl:0.9.7a
  • Openssl » Openssl » Version: 0.9.7b
    cpe:2.3:a:openssl:openssl:0.9.7b
  • Openssl » Openssl » Version: 0.9.7c
    cpe:2.3:a:openssl:openssl:0.9.7c
  • Openssl » Openssl » Version: 0.9.7d
    cpe:2.3:a:openssl:openssl:0.9.7d
  • Openssl » Openssl » Version: 0.9.7e
    cpe:2.3:a:openssl:openssl:0.9.7e
  • Openssl » Openssl » Version: 0.9.7f
    cpe:2.3:a:openssl:openssl:0.9.7f
  • Openssl » Openssl » Version: 0.9.7g
    cpe:2.3:a:openssl:openssl:0.9.7g
  • Openssl » Openssl » Version: 0.9.8
    cpe:2.3:a:openssl:openssl:0.9.8


Contact Us

Shodan ® - All rights reserved