cbcvebase.
CVE-2005-2700
published 2005-09-06

CVE-2005-2700: ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce…

PriorityP349critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
30.58%
98.0th percentile
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.

Affected

6 ranges
VendorProductVersion rangeFixed in
apachehttp_server>= 2.0.35 < 2.0.552.0.55
canonicalubuntu_linux
canonicalubuntu_linux
debianapache2< apache2 2.0.54-5 (bookworm)apache2 2.0.54-5 (bookworm)
debiandebian_linux
debiandebian_linux

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0MEDIUM
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.