CVE-2015-0204

Openssl < 0.9.8zc - Cryptographic Issue

Title source: rule

Description

The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct RSA-to-EXPORT_RSA downgrade attacks and facilitate brute-force decryption by offering a weak ephemeral RSA key in a noncompliant role, related to the "FREAK" issue. NOTE: the scope of this CVE is only client code based on OpenSSL, not EXPORT_RSA issues associated with servers or other TLS implementations.

Exploits (5)

nomisec SCANNER 5 stars
by anthophilee · poc
https://github.com/anthophilee/A2SV--SSL-VUL-Scan
nomisec SCANNER 5 stars
by AbhishekGhosh · poc
https://github.com/AbhishekGhosh/FREAK-Attack-CVE-2015-0204-Testing-Script
nomisec SCANNER 4 stars
by scottjpack · poc
https://github.com/scottjpack/Freak-Scanner
nomisec SCANNER 2 stars
by felmoltor · poc
https://github.com/felmoltor/FreakVulnChecker
nomisec WRITEUP 1 stars
by niccoX · poc
https://github.com/niccoX/patch-openssl-CVE-2014-0291_CVE-2015-0204

References (66)

... and 46 more

Scores

EPSS 0.9243
EPSS Percentile 99.7%

Details

CWE
CWE-310
Status published
Products (26)
openssl/openssl 1.0.0a
openssl/openssl 1.0.0b
openssl/openssl 1.0.0c
openssl/openssl 1.0.0d
openssl/openssl 1.0.0e
openssl/openssl 1.0.0f
openssl/openssl 1.0.0g
openssl/openssl 1.0.0h
openssl/openssl 1.0.0i
openssl/openssl 1.0.0j
... and 16 more
Published Jan 09, 2015
Tracked Since Feb 18, 2026