Severity
5.0MEDIUMNVD
OSV6.8
EPSS
7.9%
top 7.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 19
Latest updateDec 19

Description

The SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (s2_lib.c assertion failure and daemon exit) via a crafted CLIENT-MASTER-KEY message.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages6 packages

debiandebian/openssl< openssl 1.0.0c-2 (bookworm)
Debianopenssl/openssl< 1.0.0c-2+3
Ubuntuopenssl/openssl< 1.0.1f-1ubuntu2.11
NVDopenssl/openssl0.9.8ze+32

🔴Vulnerability Details

3
GHSA
GHSA-gmcw-2hjf-2h3x: The SSLv2 implementation in OpenSSL before 02022-05-14
OSV
CVE-2015-0293: The SSLv2 implementation in OpenSSL before 02015-03-19
OSV
openssl vulnerabilities2015-03-19

📋Vendor Advisories

21
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices2022-12-19
CISA ICS
Rockwell Automation Stratix 59002017-05-10
Cisco
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products2015-03-20
Red Hat
openssl: assertion failure in SSLv2 servers2015-03-19
BSD
FreeBSD-SA-15:06.openssl: Multiple OpenSSL vulnerabilities2015-03-19

🕵️Threat Intelligence

2
Tenable
[R3] LCE 5.0.0 Fixes Multiple Third-party Library Vulnerabilities2017-01-31
Tenable
[R6] OpenSSL &#039;20150319&#039; Advisory Affects Tenable Products2015-03-29

📄Research Papers

1
arXiv
Server-side verification of client behavior in cryptographic protocols2016-03-13

💬Community

9
HackerOne
Bleichenbacher oracle in SSLv2 (CVE-2016-0704)2016-06-01
HackerOne
Divide-and-conquer session key recovery in SSLv2 (CVE-2016-0703)2016-06-01
Bugzilla
CVE-2016-0704 openssl: SSLv2 Bleichenbacher protection overwrites wrong bytes for export ciphers2016-02-22
Bugzilla
CVE-2016-0800 SSL/TLS: Cross-protocol attack on TLS using SSLv2 (DROWN)2016-02-22
Bugzilla
CVE-2016-0703 openssl: Divide-and-conquer session key recovery in SSLv22016-02-22
CVE-2015-0293 — Improper Input Validation in Openssl | cvebase