CVE-2009-3555
92Vexday Risk Score
Priorize a correção. Ela exploração observada pelo VulnCheck e tem prova de conceito pública.
ssvc Actcvss 9.8epss 87%
da publicação à arma1 dias
Publicada no NVD9 de nov.
1ª PoC+1d
VulnCheck+9d
probabilidade de exploração
87%top 1% das CVEs
exploração observada
simVulnCheck
4 exploit(s) público(s)
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
n/a · n/aPoCs públicas encontradas — 4✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/10071cve_reference✓ VexDay Proofwww.exploit-db.com/exploits/10579githubgithub.com/johnwchadwick/cve-2009-3555-test-server★ 3vulncheckvulncheck.com/xdb/e36bdaa6a882não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
http://archives.neohapsis.com/archives/bugtraq/2013-11/0120.htmlhttp://blog.g-sec.lu/2009/11/tls-sslv3-renegotiation-vulnerability.htmlhttp://blogs.iss.net/archive/sslmitmiscsrf.htmlhttp://blogs.sun.com/security/entry/vulnerability_in_tls_protocol_duringhttp://clicky.me/tlsvulnhttp://extendedsubset.com/?p=8http://extendedsubset.com/Renegotiating_TLS.pdfhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02436041http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751http://kbase.redhat.com/faq/docs/DOC-20491http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html