The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Apr 12, 2012 | Nov 3, 2004 |
| Apple Osx Apache2 | — | Apply OS X security update 2005-007 | Dec 16, 2011 | Nov 3, 2004 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Nov 3, 2004 |
| Freebsd | — | Upgrade apache+mod_ssl+ipv6Upgrade apache2Upgrade ru-apache+mod_sslUpgrade apache+mod_ssl | Dec 10, 2025 | Oct 23, 2004 |
| Gentoo Linux | — | Upgrade net-www/mod_ssl.Upgrade www-servers/apache. | Oct 30, 2017 | Nov 3, 2004 |
| Suse | — | Upgrade apache2-example-pagesUpgrade apache2Upgrade libapr0Upgrade apache2-workerUpgrade apache2-preforkUpgrade apacheUpgrade apache2-docUpgrade mod_sslUpgrade apache2-devel | Feb 17, 2015 | Nov 3, 2004 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub