Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-2318

Опубликовано: 08 янв. 2018
Источник: nvd
CVSS3: 8.1
CVSS2: 6.8
EPSS Низкий

Описание

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mono-project:mono:*:*:*:*:*:*:*:*
Версия до 3.12.1 (исключая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*

EPSS

Процентиль: 79%
0.0129
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 8 лет назад

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.

CVSS3: 8.1
debian
около 8 лет назад

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers ...

CVSS3: 8.1
github
больше 3 лет назад

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.

suse-cvrf
почти 12 лет назад

Recommended update for mono-core

EPSS

Процентиль: 79%
0.0129
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-295