Vulnerability Name: | CVE-2011-1923 (CCN-65864) | ||||||||
Assigned: | 2011-02-25 | ||||||||
Published: | 2011-02-25 | ||||||||
Updated: | 2013-10-24 | ||||||||
Summary: | The Diffie-Hellman key-exchange implementation in dhm.c in PolarSSL before 0.14.2 does not properly validate a public parameter, which makes it easier for man-in-the-middle attackers to obtain the shared secret key by modifying network traffic, a related issue to CVE-2011-5095. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-310 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-1923 Source: CCN Type: PolarSSL Security Advisory 2011-01 Possible man in the middle in Diffie Hellman key exchange Source: CONFIRM Type: Vendor Advisory http://polarssl.org/trac/wiki/SecurityAdvisory201101 Source: CCN Type: SA43595 PolarSSL Diffie-Hellman Key Exchange Vulnerability Source: MISC Type: UNKNOWN http://www.cl.cam.ac.uk/~rja14/Papers/psandqs.pdf Source: MISC Type: UNKNOWN http://www.nessus.org/plugins/index.php?view=single&id=53360 Source: CCN Type: OSVDB ID: 70945 PolarSSL Diffie-Hellman Key Exchange Predictable Secret MiTM Weakness Source: BID Type: UNKNOWN 46670 Source: CCN Type: BID-46670 PolarSSL Diffie Hellman Key Exchange Security Bypass Vulnerability Source: XF Type: UNKNOWN polarssl-diffiehellman-sec-bypass(65864) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |