cbcvebase.
CVE-2014-3616
published 2014-12-08

CVE-2014-3616: nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an…

PriorityP425medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
5.65%
92.1th percentile
nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct "virtual host confusion" attacks.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiannginx< nginx 1.6.2-1 (bookworm)nginx 1.6.2-1 (bookworm)
f5nginx>= 0 < 1.6.2-11.6.2-1
f5nginx>= 0 < 1.6.2-11.6.2-1
f5nginx>= 0 < 1.6.2-11.6.2-1
f5nginx>= 0 < 1.6.2-11.6.2-1
f5nginx>= 0.5.6 < 1.6.21.6.2
f5nginx>= 1.7.0 < 1.7.51.7.5

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.