7.5

CVE-2008-7128

The ssl_parse_client_key_exchange function in XySSL before 0.9 does not protect against certain Bleichenbacher attacks using chosen ciphertext, which allows remote attackers to recover keys via unspecified vectors.

Data is provided by the National Vulnerability Database (NVD)
XysslXyssl Version <= 0.8
XysslXyssl Version0.1
XysslXyssl Version0.2
XysslXyssl Version0.3
XysslXyssl Version0.4
XysslXyssl Version0.5
XysslXyssl Version0.6
XysslXyssl Version0.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.52% 0.641
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P