CVE-2015-3193
high-risk
Published 2015-12-06
The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and produces incorrect output, which makes it easier for remote attackers to obtain sensitive private-key information via an attack against use of a (1) Diffie-Hellman (DH) or (2) Diffie-Hellman Ephemeral (DHE) ciphersuite.
Do I need to act?
!
35.2% chance of exploitation in next 30 days
EPSS score — higher than 65% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (11)
References (44)
Third Party Advisory
http://fortiguard.com/advisory/openssl-advisory-december-2015
Third Party Advisory
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759
Third Party Advisory
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
Vendor Advisory
http://openssl.org/news/secadv/20151203.txt
Third Party Advisory
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20...
Third Party Advisory
http://www.fortiguard.com/advisory/openssl-advisory-december-2015
Third Party Advisory
http://www.securityfocus.com/bid/78705
Third Party Advisory
http://www.securityfocus.com/bid/91787
Third Party Advisory
http://www.securitytracker.com/id/1034294
Third Party Advisory
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slack...
Third Party Advisory
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slack...
Third Party Advisory
http://www.ubuntu.com/usn/USN-2830-1
Third Party Advisory
https://blog.fuzzing-project.org/31-Fuzzing-Math-miscalculations-in-OpenSSLs-BN_...
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1288317
Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c...
and 24 more references
58
/ 100
high-risk
Severity
26/34 · High
Exploitability
16/34 · Moderate
Exposure
16/34 · Moderate