CVE-1999-0428 — Session Fixation in Openssl
Severity
7.5HIGHNVD
EPSS
0.3%
top 48.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 22
Latest updateApr 19
Description
OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4
Affected Packages3 packages
🔴Vulnerability Details
2📋Vendor Advisories
2📐Framework References
1CAPEC▶
Reusing Session IDs (aka Session Replay)
💬Community
1Bugzilla▶
CVE-1999-0428 openssl: allow remote attackers to reuse SSL sessions and bypass access controls↗2020-10-27