Описание
An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero MasterSecret that can decrypt secret data.
Ссылки
- ExploitThird Party Advisory
- Permissions RequiredVendor Advisory
- ExploitThird Party Advisory
- Permissions RequiredVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.5.1 (включая)
cpe:2.3:a:matrixssl:matrixssl:*:*:*:*:*:*:*:*
EPSS
Процентиль: 71%
0.00672
Низкий
7.5 High
CVSS3
Дефекты
CWE-665
CWE-665
Связанные уязвимости
CVSS3: 7.5
debian
около 3 лет назад
An issue in MatrixSSL 4.5.1-open and earlier leads to failure to secur ...
CVSS3: 7.5
github
около 3 лет назад
An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero MasterSecret that can decrypt secret data.
EPSS
Процентиль: 71%
0.00672
Низкий
7.5 High
CVSS3
Дефекты
CWE-665
CWE-665