Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x384-p6fm-q24w

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack," aka "TLS Server Certificate Renegotiation Vulnerability."

SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack," aka "TLS Server Certificate Renegotiation Vulnerability."

EPSS

Процентиль: 94%
0.1504
Средний

Связанные уязвимости

nvd
около 11 лет назад

SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack," aka "TLS Server Certificate Renegotiation Vulnerability."

fstec
около 11 лет назад

Уязвимость браузера Internet Explorer, позволяющая злоумышленнику получить несанкционированный доступ к передаваемым данным

EPSS

Процентиль: 94%
0.1504
Средний