OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade openssl-perlUpgrade openssl-develUpgrade openssl | Dec 1, 2016 | Dec 6, 2010 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Dec 6, 2010 |
| Hp Ilo | — | Upgrade HP iLO 3 to version 1.20Upgrade HP iLO 2 to version 2.06 | Aug 1, 2018 | Dec 6, 2010 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 5, 2026 | Dec 6, 2010 |
| Oracle_linux | — | Upgrade openssl-develUpgrade openssl-perlUpgrade openssl | Oct 16, 2024 | Dec 6, 2010 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 2, 2010 |
| Suse | — | Upgrade openssl-develUpgrade openssl-x86Upgrade openssl-64bitUpgrade openssl-devel-64bitUpgrade openssl-devel-32bitUpgrade opensslUpgrade openssl-32bitUpgrade openssl-docUpgrade sap-aio-release | Dec 12, 2013 | Dec 6, 2010 |
| Ubuntu | — | Upgrade libssl0.9.8 | Nov 8, 2024 | Dec 6, 2010 |
| Vmsa 2011 0013 | — | Upgrade VMware ESX 4.1 to build number 502767Upgrade VMware ESX 4.0 to build number 660575 | Nov 22, 2011 | Dec 6, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub