5.8

CVE-2011-4354

crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 and P-384 NIST elliptic curves, which allows remote attackers to obtain the private key of a TLS server via multiple handshake attempts.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenSSLOpenSSL HwPlatformx86 Version <= 0.9.8g
OpenSSLOpenSSL Version0.9.1c HwPlatformx86
OpenSSLOpenSSL Version0.9.2b HwPlatformx86
OpenSSLOpenSSL Version0.9.3 HwPlatformx86
OpenSSLOpenSSL Version0.9.3a HwPlatformx86
OpenSSLOpenSSL Version0.9.4 HwPlatformx86
OpenSSLOpenSSL Version0.9.5 HwPlatformx86
OpenSSLOpenSSL Version0.9.5 Updatebeta1 HwPlatformx86
OpenSSLOpenSSL Version0.9.5 Updatebeta2 HwPlatformx86
OpenSSLOpenSSL Version0.9.5a HwPlatformx86
OpenSSLOpenSSL Version0.9.5a Updatebeta1 HwPlatformx86
OpenSSLOpenSSL Version0.9.5a Updatebeta2 HwPlatformx86
OpenSSLOpenSSL Version0.9.6 HwPlatformx86
OpenSSLOpenSSL Version0.9.6 Updatebeta1 HwPlatformx86
OpenSSLOpenSSL Version0.9.6 Updatebeta2 HwPlatformx86
OpenSSLOpenSSL Version0.9.6 Updatebeta3 HwPlatformx86
OpenSSLOpenSSL Version0.9.6a HwPlatformx86
OpenSSLOpenSSL Version0.9.6a Updatebeta1 HwPlatformx86
OpenSSLOpenSSL Version0.9.6a Updatebeta2 HwPlatformx86
OpenSSLOpenSSL Version0.9.6a Updatebeta3 HwPlatformx86
OpenSSLOpenSSL Version0.9.6b HwPlatformx86
OpenSSLOpenSSL Version0.9.6c HwPlatformx86
OpenSSLOpenSSL Version0.9.6d HwPlatformx86
OpenSSLOpenSSL Version0.9.6e HwPlatformx86
OpenSSLOpenSSL Version0.9.6f HwPlatformx86
OpenSSLOpenSSL Version0.9.6g HwPlatformx86
OpenSSLOpenSSL Version0.9.6h HwPlatformx86
OpenSSLOpenSSL Version0.9.6i HwPlatformx86
OpenSSLOpenSSL Version0.9.6j HwPlatformx86
OpenSSLOpenSSL Version0.9.6k HwPlatformx86
OpenSSLOpenSSL Version0.9.6l HwPlatformx86
OpenSSLOpenSSL Version0.9.6m HwPlatformx86
OpenSSLOpenSSL Version0.9.7 HwPlatformx86
OpenSSLOpenSSL Version0.9.7 Updatebeta1 HwPlatformx86
OpenSSLOpenSSL Version0.9.7 Updatebeta2 HwPlatformx86
OpenSSLOpenSSL Version0.9.7 Updatebeta3 HwPlatformx86
OpenSSLOpenSSL Version0.9.7 Updatebeta4 HwPlatformx86
OpenSSLOpenSSL Version0.9.7 Updatebeta5 HwPlatformx86
OpenSSLOpenSSL Version0.9.7 Updatebeta6 HwPlatformx86
OpenSSLOpenSSL Version0.9.7a HwPlatformx86
OpenSSLOpenSSL Version0.9.7b HwPlatformx86
OpenSSLOpenSSL Version0.9.7c HwPlatformx86
OpenSSLOpenSSL Version0.9.7d HwPlatformx86
OpenSSLOpenSSL Version0.9.7e HwPlatformx86
OpenSSLOpenSSL Version0.9.7f HwPlatformx86
OpenSSLOpenSSL Version0.9.7g HwPlatformx86
OpenSSLOpenSSL Version0.9.7h HwPlatformx86
OpenSSLOpenSSL Version0.9.7i HwPlatformx86
OpenSSLOpenSSL Version0.9.7j HwPlatformx86
OpenSSLOpenSSL Version0.9.7k HwPlatformx86
OpenSSLOpenSSL Version0.9.7l HwPlatformx86
OpenSSLOpenSSL Version0.9.7m HwPlatformx86
OpenSSLOpenSSL Version0.9.8 HwPlatformx86
OpenSSLOpenSSL Version0.9.8a HwPlatformx86
OpenSSLOpenSSL Version0.9.8b HwPlatformx86
OpenSSLOpenSSL Version0.9.8c HwPlatformx86
OpenSSLOpenSSL Version0.9.8d HwPlatformx86
OpenSSLOpenSSL Version0.9.8e HwPlatformx86
OpenSSLOpenSSL Version0.9.8f HwPlatformx86
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.595
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N