cbcvebase.
CVE-2011-5095
published 2012-06-20

CVE-2011-5095: The Diffie-Hellman key-exchange implementation in OpenSSL 0.9.8, when FIPS mode is enabled, does not properly validate a public parameter, which makes it…

PriorityP417medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
2.09%
79.5th percentile
The Diffie-Hellman key-exchange implementation in OpenSSL 0.9.8, when FIPS mode is enabled, does not properly validate a public parameter, which makes it easier for man-in-the-middle attackers to obtain the shared secret key by modifying network traffic, a related issue to CVE-2011-1923.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianopenssl< openssl 0.9.8a-1 (bookworm)openssl 0.9.8a-1 (bookworm)
opensslopenssl
opensslopenssl>= 0 < 0.9.8a-10.9.8a-1
opensslopenssl>= 0 < 0.9.8a-10.9.8a-1
opensslopenssl>= 0 < 0.9.8a-10.9.8a-1
opensslopenssl>= 0 < 0.9.8a-10.9.8a-1
polarsslpolarssl<= 0.14.0
polarsslpolarssl
polarsslpolarssl
polarsslpolarssl
polarsslpolarssl
polarsslpolarssl
polarsslpolarssl
polarsslpolarssl

CVSS provenance

nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.