OpenSSL before 1.0.0c, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Oct 9, 2015 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | Dec 6, 2010 |
| Hpux | — | Update openssl.OPENSSL-LIB to the latest versionUpdate openssl.OPENSSL-MAN to the latest versionUpdate openssl.OPENSSL-CONF to the latest versionUpdate openssl.OPENSSL-INC to the latest versionUpdate openssl.OPENSSL-RUN to the latest versionUpdate openssl.OPENSSL-PRNG to the latest versionUpdate openssl.OPENSSL-CER to the latest versionUpdate openssl.OPENSSL-MIS to the latest versionUpdate openssl.OPENSSL-DOC to the latest versionUpdate openssl.OPENSSL-SRC to the latest versionUpdate openssl.OPENSSL-PVT to the latest version | Aug 11, 2017 | Dec 6, 2010 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Jan 26, 2012 | Dec 6, 2010 |
| Suse | — | Upgrade libopenssl0_9_8-x86Upgrade libopenssl-develUpgrade libopenssl0_9_8-hmacUpgrade libopenssl0_9_8-hmac-32bitUpgrade libopenssl0_9_8-32bitUpgrade libopenssl0_9_8Upgrade openssl-docUpgrade openssl | Aug 9, 2024 | Jul 9, 2013 |
| Vmsa 2012 0013 | — | Upgrade VMware ESXi 5.0 to build number 912577Upgrade VMware ESX 4.1 to build number 800380Upgrade VMware ESXi 4.1 to build number 800380 | Sep 17, 2012 | Dec 6, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub