Vulnerability Name:

CVE-2014-3572

Assigned:2014-05-14
Published:2015-01-05
Updated:2017-11-14
Summary:The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct ECDHE-to-ECDH downgrade attacks and trigger a loss of forward secrecy by omitting the ServerKeyExchange message.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
1.2 Low (CCN CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:N)
0.9 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (REDHAT CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-310
References:Source: CONFIRM
Type: UNKNOWN
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10679

Source: APPLE
Type: UNKNOWN
APPLE-SA-2015-04-08-2

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2015:0130

Source: SUSE
Type: UNKNOWN
SUSE-SU-2015:0578

Source: SUSE
Type: UNKNOWN
SUSE-SU-2015:0946

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2015:1277

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2016:0640

Source: HP
Type: UNKNOWN
HPSBUX03162

Source: HP
Type: UNKNOWN
SSRT101885

Source: HP
Type: UNKNOWN
SSRT101987

Source: HP
Type: UNKNOWN
HPSBHF03289

Source: HP
Type: UNKNOWN
HPSBOV03318

Source: HP
Type: UNKNOWN
HPSBMU03380

Source: HP
Type: UNKNOWN
HPSBMU03409

Source: HP
Type: UNKNOWN
HPSBMU03396

Source: HP
Type: UNKNOWN
HPSBMU03413

Source: HP
Type: UNKNOWN
HPSBMU03397

Source: REDHAT
Type: UNKNOWN
RHSA-2015:0066

Source: CISCO
Type: UNKNOWN
20150310 Multiple Vulnerabilities in OpenSSL (January 2015) Affecting Cisco Products

Source: DEBIAN
Type: UNKNOWN
DSA-3125

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2015:019

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2015:062

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html

Source: BID
Type: UNKNOWN
71942

Source: SECTRACK
Type: UNKNOWN
1033378

Source: CONFIRM
Type: UNKNOWN
https://bto.bluecoat.com/security-advisory/sa88

Source: XF
Type: UNKNOWN
openssl-cve20143572-weak-security(99705)

Source: CONFIRM
Type: UNKNOWN
https://github.com/openssl/openssl/commit/b15f8769644b00ef7283521593360b7b2135cb63

Source: CONFIRM
Type: UNKNOWN
https://kc.mcafee.com/corporate/index?page=content&id=SB10102

Source: CONFIRM
Type: UNKNOWN
https://kc.mcafee.com/corporate/index?page=content&id=SB10108

Source: CONFIRM
Type: UNKNOWN
https://support.apple.com/HT204659

Source: CONFIRM
Type: UNKNOWN
https://support.citrix.com/article/CTX216642

Source: CONFIRM
Type: VENDOR_ADVISORY
https://www.openssl.org/news/secadv_20150108.txt

Vulnerable Configuration:Configuration 1:
  • cpe:/a:openssl:openssl:0.9.8zc:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0a:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0b:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0c:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0d:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0e:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0f:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0g:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0h:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0i:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0j:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0k:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0l:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0m:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0n:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0o:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1i:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1j:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*

  • Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20143572
    V
    CVE-2014-3572
    2017-11-19
    oval:org.cisecurity:def:205
    P
    DSA-3125-1 -- openssl -- security update
    2016-02-08
    oval:org.mitre.oval:def:28606
    V
    Potential security vulnerabilities have been identified with HP-UX running OpenSSL.These vulnerabilities could be exploited remotely to create a remote Denial of Service(DoS) and other vulnerabilites.
    2015-05-11
    oval:com.redhat.rhsa:def:20150066
    P
    RHSA-2015:0066: openssl security update (Moderate)
    2015-01-21
    oval:com.ubuntu.precise:def:20143572000
    V
    CVE-2014-3572 on Ubuntu 12.04 LTS (precise) - low.
    2015-01-08
    oval:com.ubuntu.trusty:def:20143572000
    V
    CVE-2014-3572 on Ubuntu 14.04 LTS (trusty) - low.
    2015-01-08
    oval:com.ubuntu.xenial:def:20143572000
    V
    CVE-2014-3572 on Ubuntu 16.04 LTS (xenial) - low.
    2015-01-08
    BACK
    openssl openssl 0.9.8zc
    openssl openssl 1.0.0a
    openssl openssl 1.0.0b
    openssl openssl 1.0.0c
    openssl openssl 1.0.0d
    openssl openssl 1.0.0e
    openssl openssl 1.0.0f
    openssl openssl 1.0.0g
    openssl openssl 1.0.0h
    openssl openssl 1.0.0i
    openssl openssl 1.0.0j
    openssl openssl 1.0.0k
    openssl openssl 1.0.0l
    openssl openssl 1.0.0m
    openssl openssl 1.0.0n
    openssl openssl 1.0.0o
    openssl openssl 1.0.1a
    openssl openssl 1.0.1b
    openssl openssl 1.0.1c
    openssl openssl 1.0.1d
    openssl openssl 1.0.1e
    openssl openssl 1.0.1f
    openssl openssl 1.0.1g
    openssl openssl 1.0.1h
    openssl openssl 1.0.1i
    openssl openssl 1.0.1j
    redhat enterprise_linux 7
    redhat enterprise_linux 6