OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.
CVSS Details
- CVSS 3.1 Base Score: 5.9
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Airport | — | Apply OS X security update 2011-004 | Aug 28, 2015 | Dec 6, 2010 |
| Apple Osx Openssl | — | Upgrade macOS to the latest version | Dec 16, 2011 | Dec 6, 2010 |
| Centos_linux | — | Upgrade opensslUpgrade openssl-perl | Dec 1, 2016 | Dec 6, 2010 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Dec 6, 2010 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | Dec 6, 2010 |
| Hp Ilo | — | Upgrade HP iLO 3 to version 1.20Upgrade HP iLO 2 to version 2.06 | Aug 1, 2018 | Dec 6, 2010 |
| Hpux | — | Update openssl.OPENSSL-RUN to the latest versionUpdate openssl.OPENSSL-DOC to the latest versionUpdate openssl.OPENSSL-LIB to the latest versionUpdate openssl.OPENSSL-PVT to the latest versionUpdate openssl.OPENSSL-MAN to the latest versionUpdate openssl.OPENSSL-PRNG to the latest versionUpdate openssl.OPENSSL-INC to the latest versionUpdate openssl.OPENSSL-CONF to the latest versionUpdate openssl.OPENSSL-SRC to the latest versionUpdate openssl.OPENSSL-CER to the latest versionUpdate openssl.OPENSSL-MIS to the latest version | Aug 11, 2017 | Dec 6, 2010 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Dec 6, 2010 | Dec 6, 2010 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory2 | Nov 30, 2017 | Dec 6, 2010 |
| Oracle_linux | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl-develUpgrade openssl-static | Oct 16, 2024 | Dec 6, 2010 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 2, 2010 |
| Suse | — | Upgrade curl-openssl1Upgrade libcurl4-openssl1-32bitUpgrade openssl-docUpgrade libcurl4-openssl1Upgrade libcurl4Upgrade libopenssl0_9_8-x86Upgrade curlUpgrade libcurl4-x86Upgrade libopenssl0_9_8Upgrade libcurl-develUpgrade libopenssl0_9_8-hmacUpgrade libopenssl-develUpgrade libopenssl0_9_8-32bitUpgrade libcurl4-32bitUpgrade opensslUpgrade libopenssl0_9_8-hmac-32bit | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libssl0.9.8 | Nov 8, 2024 | Dec 6, 2010 |
| Vmsa 2011 0013 | — | Upgrade VMware ESX 4.0 to build number 660575Upgrade VMware ESX 4.1 to build number 502767 | Nov 22, 2011 | Dec 6, 2010 |
| Vmsa 2012 0013 | — | Upgrade VMware ESX 4.1 to build number 800380Upgrade VMware ESXi 4.1 to build number 800380Upgrade VMware ESXi 5.0 to build number 912577 | Sep 17, 2012 | Dec 6, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub