cbcvebase.
CVE-2015-4000
published 2015-05-21

CVE-2015-4000: The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which…

low3.7CVSS 3.1
AVNACHPRNUINSUCNILAN
EXPLOIT
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

Affected

50 ranges· showing 25
VendorProductVersion rangeFixed in
appleios
appleiphone_os<= 8.3
applemac_os_x<= 10.10.3
appleos_x_yosemite_v10.10.4_and_security_update_2015-005
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiannss< nss 2:3.19.1-1 (bookworm)nss 2:3.19.1-1 (bookworm)
debianopenjdk-8< nss 2:3.19.1-1 (bookworm)nss 2:3.19.1-1 (bookworm)
debianopenssl< nss 2:3.19.1-1 (bookworm)nss 2:3.19.1-1 (bookworm)
geddyjsgeddy>= 0 < 13.0.813.0.8
hphp-ux
ibmcontent_manager
mozillafirefox
mozillafirefox
mozillafirefox>= 0 < 39.0+build5-0ubuntu0.14.04.139.0+build5-0ubuntu0.14.04.1
mozillafirefox_esr
mozillafirefox_os
mozillanetwork_security_services
mozillanss>= 0 < 2:3.19.1-12:3.19.1-1
mozillanss>= 0 < 2:3.19.1-12:3.19.1-1
mozillanss>= 0 < 2:3.19.1-12:3.19.1-1

CVSS provenance

nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
osv9.8CRITICAL