CVE-2014-3572Use of a Broken or Risky Cryptographic Algorithm in Openssl

Severity
7.5HIGHNVD
NVD5.0OSV5.0
EPSS
8.8%
top 7.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 9
Latest updateMay 17

Description

The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct ECDHE-to-ECDH downgrade attacks and trigger a loss of forward secrecy by omitting the ServerKeyExchange message.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages8 packages

debiandebian/openssl< openssl 1.0.1k-1 (bookworm)
Debianopenssl/openssl< 1.0.1k-1+3
Ubuntuopenssl/openssl< 1.0.1f-1ubuntu2.8
NVDopenssl/openssl0.9.8zc+25
NVDdell/bsafe4.0.04.0.8+1

🔴Vulnerability Details

4
GHSA
GHSA-38r9-r99v-9jf8: The ssl3_get_key_exchange function in s3_clnt2022-05-17
GHSA
GHSA-29q6-xr6f-w93f: EMC RSA BSAFE Micro Edition Suite (MES) 42022-05-13
OSV
openssl vulnerabilities2015-01-12
OSV
CVE-2014-3572: The ssl3_get_key_exchange function in s3_clnt2015-01-09

📋Vendor Advisories

14
Cisco
Multiple Vulnerabilities in OpenSSL (January 2015) Affecting Cisco Products2015-03-10
BSD
FreeBSD-SA-15:01.openssl: OpenSSL multiple vulnerabilities2015-01-14
Ubuntu
OpenSSL vulnerabilities2015-01-12
Red Hat
openssl: ECDH downgrade bug fix2015-01-05
Debian
CVE-2014-3572: openssl - The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0...2014

🕵️Threat Intelligence

1
Tenable
[R3] LCE 5.0.0 Fixes Multiple Third-party Library Vulnerabilities2017-01-31

💬Community

2
Bugzilla
CVE-2014-3572 openssl: ECDH downgrade bug fix2015-01-08
Bugzilla
NSS incorrectly permits skipping of ServerKeyExchange2014-10-21