Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-3511

The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 1.0.1 before 1.0.1i allows man-in-the-middle attackers to force the use of TLS 1.0 by triggering ClientHello message fragmentation in communication between a client and server that both support later TLS versions, related to a "protocol downgrade" issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.07
EPSS Ranking 91.1%
CVSS Severity
CVSS v2 Score 4.3
References
Products affected by CVE-2014-3511
  • Openssl » Openssl » Version: 1.0.0
    cpe:2.3:a:openssl:openssl:1.0.0
  • Openssl » Openssl » Version: 1.0.0a
    cpe:2.3:a:openssl:openssl:1.0.0a
  • Openssl » Openssl » Version: 1.0.0b
    cpe:2.3:a:openssl:openssl:1.0.0b
  • Openssl » Openssl » Version: 1.0.0c
    cpe:2.3:a:openssl:openssl:1.0.0c
  • Openssl » Openssl » Version: 1.0.0d
    cpe:2.3:a:openssl:openssl:1.0.0d
  • Openssl » Openssl » Version: 1.0.0e
    cpe:2.3:a:openssl:openssl:1.0.0e
  • Openssl » Openssl » Version: 1.0.0f
    cpe:2.3:a:openssl:openssl:1.0.0f
  • Openssl » Openssl » Version: 1.0.0g
    cpe:2.3:a:openssl:openssl:1.0.0g
  • Openssl » Openssl » Version: 1.0.0h
    cpe:2.3:a:openssl:openssl:1.0.0h
  • Openssl » Openssl » Version: 1.0.0i
    cpe:2.3:a:openssl:openssl:1.0.0i
  • Openssl » Openssl » Version: 1.0.0j
    cpe:2.3:a:openssl:openssl:1.0.0j
  • Openssl » Openssl » Version: 1.0.0k
    cpe:2.3:a:openssl:openssl:1.0.0k
  • Openssl » Openssl » Version: 1.0.0l
    cpe:2.3:a:openssl:openssl:1.0.0l
  • Openssl » Openssl » Version: 1.0.0m
    cpe:2.3:a:openssl:openssl:1.0.0m
  • Openssl » Openssl » Version: 1.0.1
    cpe:2.3:a:openssl:openssl:1.0.1
  • Openssl » Openssl » Version: 1.0.1a
    cpe:2.3:a:openssl:openssl:1.0.1a
  • Openssl » Openssl » Version: 1.0.1b
    cpe:2.3:a:openssl:openssl:1.0.1b
  • Openssl » Openssl » Version: 1.0.1c
    cpe:2.3:a:openssl:openssl:1.0.1c
  • Openssl » Openssl » Version: 1.0.1d
    cpe:2.3:a:openssl:openssl:1.0.1d
  • Openssl » Openssl » Version: 1.0.1e
    cpe:2.3:a:openssl:openssl:1.0.1e
  • Openssl » Openssl » Version: 1.0.1f
    cpe:2.3:a:openssl:openssl:1.0.1f
  • Openssl » Openssl » Version: 1.0.1g
    cpe:2.3:a:openssl:openssl:1.0.1g
  • Openssl » Openssl » Version: 1.0.1h
    cpe:2.3:a:openssl:openssl:1.0.1h


Contact Us

Shodan ® - All rights reserved