CVE-2018-12384
Last modified
CVE-2018-12384 is a vulnerability of currently unknown severity. When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. EPSS estimates a 1.50% chance of exploitation in the next 30 days.
Description
When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Network Security Services | < 3.39 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=CVE-2018-12384Issue Tracking, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=CVE-2018-12384Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-12384?
How severe is CVE-2018-12384?
How do I fix CVE-2018-12384?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-12379When the Mozilla Updater opens a MAR format file which conta…
- CVE-2018-1238Dell EMC ScaleIO versions prior to 2.5, contain a command in…
- CVE-2018-12380Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-12381Manually dragging and dropping an Outlook email message into…
- CVE-2018-12382The displayed addressbar URL can be spoofed on Firefox for A…
- CVE-2018-12383If a user saved passwords before Firefox 58 and then later s…
- CVE-2018-12385A potentially exploitable crash in TransportSecurityInfo use…
- CVE-2018-12386A vulnerability in register allocation in JavaScript can lea…
- CVE-2018-12387A vulnerability where the JavaScript JIT compiler inlines Ar…
- CVE-2018-12388Mozilla developers and community members reported memory saf…
- CVE-2018-12389Mozilla developers and community members reported memory saf…
- CVE-2018-1239Dell EMC Unity Operating Environment (OE) versions prior to …
Are you affected by CVE-2018-12384?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
