CVE-2019-14852

HIGH

3scale API Management - Use of Broken TLS 1.0 Cryptographic Algorithm

Title source: llm
STIX 2.1

Description

A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weaker protocol and break its encryption, gaining access to unauthorized information. Version shipped in Red Hat 3scale API Management Platform is vulnerable to this issue.

References (1)

Core 1
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1758208

Scores

CVSS v3 7.5
EPSS 0.0007
EPSS Percentile 21.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-327
Status published
Products (1)
redhat/3scale_api_management 2.0
Published Mar 18, 2021
Tracked Since Feb 18, 2026