CVE-2020-1596
published 2020-09-11CVE-2020-1596: A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfully exploited this vulnerability could…
PriorityP422medium5.3CVSS 3.1
AVAACHPRNUINSUCHINAN
EPSS
0.90%
55.5th percentile
A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfully exploited this vulnerability could obtain information to further compromise a users's encrypted transmission channel.
To exploit the vulnerability, an attacker would have to conduct a man-in-the-middle attack.
The update addresses the vulnerability by correcting how TLS components use hash algorithms.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1607 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_arm64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_x64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1909 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_7 | >= 6.1.0 < publication | publication |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_8.1 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < publication | publication |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.0 < publication | publication |
| microsoft | windows_server_2012 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cm57-v77w-q64x: A information disclosure vulnerability exists when TLS components use weak hash algorithms, aka 'TLS Information Disclosure Vulnerability'
ghsa_unreviewed·2022-05-24
CVE-2020-1596 [MEDIUM] CWE-327 GHSA-cm57-v77w-q64x: A information disclosure vulnerability exists when TLS components use weak hash algorithms, aka 'TLS Information Disclosure Vulnerability'
A information disclosure vulnerability exists when TLS components use weak hash algorithms, aka 'TLS Information Disclosure Vulnerability'.
Microsoft
TLS Information Disclosure Vulnerability
vendor_msrc·2020-09-08·CVSS 5.4
CVE-2020-1596 [MEDIUM] TLS Information Disclosure Vulnerability
TLS Information Disclosure Vulnerability
Description: A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfully exploited this vulnerability could obtain information to further compromise a users's encrypted transmission channel.
To exploit the vulnerability, an attacker would have to conduct a man-in-the-middle attack.
The update addresses the vulnerability by correcting how TLS components use hash algorithms.
FAQ: What type of information disclosure does the CVE address?
This CVE addresses protocol limitations associated with TLS_DHE ephemeral key reusage which can lead to key disclosure.
Are there any advice regarding using TLS_DHE keys?
The industry has mostly stopped using TLS_DHE. Microsoft advises customers to disable
No detection rules found.
No public exploits indexed.
Trendmicro
September Patch Tuesday Updates Exchange, SharePoint
blogs_trendmicro·2020-09-09·CVSS 7.5
[HIGH] September Patch Tuesday Updates Exchange, SharePoint
## September Patch Tuesday Updates Exchange, SharePoint
This month’s update includes 129 updates for the Microsoft Office suite, with 15 specifically addressing SharePoint vulnerabilities.
By: Trend Micro 2020/09/09 Read time: ( words)
Save to Folio
This month’s update includes 129 updates for the Microsoft Office suite, with 15 specifically addressing SharePoint vulnerabilities. Of the total number, 23 have been rated Critical and 105 as Important. No zero days have been observed, but four vulnerabilities are under close scrutiny for their potential abuse. Specifically, CVE-2020-16875 can be exploited for remote code execution (RCE), CVE-2020-1596 for man-in-the-middle (MiTM) attacks, while CVE-2020-0836 and CVE-2020-1228 can be abused for domain name system (DNS) denial of service (D
Trendmicro
September Patch Tuesday Updates Exchange, SharePoint
blogs_trendmicro·2020-09-09·CVSS 7.5
[HIGH] September Patch Tuesday Updates Exchange, SharePoint
## September Patch Tuesday Updates Exchange, SharePoint
This month’s update includes 129 updates for the Microsoft Office suite, with 15 specifically addressing SharePoint vulnerabilities.
By: Trend Micro Sep 09, 2020 Read time: ( words)
Save to Folio
This month’s update includes 129 updates for the Microsoft Office suite, with 15 specifically addressing SharePoint vulnerabilities. Of the total number, 23 have been rated Critical and 105 as Important. No zero days have been observed, but four vulnerabilities are under close scrutiny for their potential abuse. Specifically, CVE-2020-16875 can be exploited for remote code execution (RCE), CVE-2020-1596 for man-in-the-middle (MiTM) attacks, while CVE-2020-0836 and CVE-2020-1228 can be abused for domain name system (DNS) denial of service
Trendmicro
September Patch Tuesday Updates Exchange, SharePoint
blogs_trendmicro·2020-09-09·CVSS 7.5
[HIGH] September Patch Tuesday Updates Exchange, SharePoint
# September Patch Tuesday Updates Exchange, SharePoint
This month’s update includes 129 updates for the Microsoft Office suite, with 15 specifically addressing SharePoint vulnerabilities.
By: Trend Micro
2020/09/09
Read time: ( words)
Save to Folio
This month’s update includes 129 updates for the Microsoft Office suite, with 15 specifically addressing SharePoint vulnerabilities. Of the total number, 23 have been rated Critical and 105 as Important. No zero days have been observed, but four vulnerabilities are under close scrutiny for their potential abuse. Specifically, CVE-2020-16875 can be exploited for remote code execution (RCE), CVE-2020-1596 for man-in-the-middle (MiTM) attacks, while CVE-2020-0836 and CVE-2020-1228 can be abused for domain name system (DNS) denial of service (D
2020-09-11
Published