CVE-2018-12384

MEDIUM

Network Security Services < 3.39 - Predictable PRNG Seed via SSLv2 ClientHello Handling

Title source: llm
STIX 2.1

Description

When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.

References (2)

Core 2
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=CVE-2018-12384

Scores

CVSS v3 5.9
EPSS 0.0062
EPSS Percentile 70.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-335
Status published
Products (1)
mozilla/network_security_services < 3.39
Published Apr 29, 2019
Tracked Since Feb 18, 2026