CVE-2014-3511

UnknownEPSS 13.33%

Last modified

CVE-2014-3511 is a vulnerability of currently unknown severity. The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 1.0.1 before 1.0.1i allows man-in-the-middle attackers to force the use of TLS 1.0 by triggering ClientHello message fragmentation in communication between a client and server that both support later TLS versions, related to a "protocol downgrade" issue.. EPSS estimates a 13.33% chance of exploitation in the next 30 days.

Description

The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 1.0.1 before 1.0.1i allows man-in-the-middle attackers to force the use of TLS 1.0 by triggering ClientHello message fragmentation in communication between a client and server that both support later TLS versions, related to a "protocol downgrade" issue.

Metrics

EPSS Probability
13.33%

95.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
OpensslOpenssl1.0.0
OpensslOpenssl1.0.0a
OpensslOpenssl1.0.0b
OpensslOpenssl1.0.0c
OpensslOpenssl1.0.0d
OpensslOpenssl1.0.0e
OpensslOpenssl1.0.0f
OpensslOpenssl1.0.0g
OpensslOpenssl1.0.0h
OpensslOpenssl1.0.0i
OpensslOpenssl1.0.0j
OpensslOpenssl1.0.0k
OpensslOpenssl1.0.0l
OpensslOpenssl1.0.0m
OpensslOpenssl1.0.1
OpensslOpenssl1.0.1a
OpensslOpenssl1.0.1b
OpensslOpenssl1.0.1c
OpensslOpenssl1.0.1d
OpensslOpenssl1.0.1e
OpensslOpenssl1.0.1f
OpensslOpenssl1.0.1g
OpensslOpenssl1.0.1h

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-3511?
The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 1.0.1 before 1.0.1i allows man-in-the-middle attackers to force the use of TLS 1.0 by triggering ClientHello message fragmentation in communication between a client and server that both support later TLS versions, related to a "protocol downgrade" issue.
How severe is CVE-2014-3511?
Severity scoring for CVE-2014-3511 is pending analysis. The EPSS model estimates a 13.33% probability of exploitation in the next 30 days.
How do I fix CVE-2014-3511?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-3511?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST