Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-3389

71
FAUCET Score

CVE-2011-3389, known as the "BEAST" attack, is a vulnerability in the SSL protocol affecting various products including Microsoft Windows, Internet Explorer, Firefox, Chrome, and Opera. It allows man-in-the-middle attackers to decrypt plaintext HTTP headers from HTTPS sessions. The vulnerability has a CVSS score of 4.3 (medium severity), indicating a network-based attack with medium complexity and potential for partial confidentiality compromise. While no active exploitation is confirmed, a Metasploit module exists for SSL/TLS version detection, and it has garnered significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:microsoft:internet_explorer:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:opera:opera_browser:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
73.33%
Probability of exploitation in next 30 days
EPSS Percentile
99.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Metasploit: SSL/TLS Version Detection · Oct 14, 2014
This CVE's current EPSS score of 0.7333 is in the 100th percentile among its peer group of 19,954 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (30)

jitsipatch availablevia llm_extracted
Fixed in: 7.23.1
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.4.2-ibm-0:1.4.2.13.11-1jpp.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.6.0-ibm-1:1.6.0.10.0-1jpp.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: java-1.6.0-openjdk-1:1.6.0.0-1.23.1.9.10.el5_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: java-1.6.0-openjdk-1:1.6.0.0-1.40.1.9.10.el6_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 SupplementaryFixed in: java-1.6.0-sun-1:1.6.0.29-1jpp.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 SupplementaryFixed in: java-1.6.0-ibm-1:1.6.0.10.0-1jpp.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.4Fixed in: java-1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el6_4
View patch
redhatpatch availablevia redhat_api
Product: RHEL 4 for SAPFixed in: java-1.4.2-ibm-sap-0:1.4.2.13.11.sap-1jpp.1.el4
View patch
redhatpatch availablevia redhat_api
Product: RHEL 5 for SAPFixed in: java-1.4.2-ibm-sap-0:1.4.2.13.11.sap-1jpp.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.6.0-sun-1:1.6.0.29-1jpp.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.4.2-ibm-0:1.4.2.13.11-1jpp.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.6.0-ibm-1:1.6.0.10.0-1jpp.2.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.5.0-ibm-1:1.5.0.13.1-1jpp.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: java-1.5.0-ibm-1:1.5.0.13.1-1jpp.2.el6_2
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.6.0-sun-1:1.6.0.29-1jpp.1.el4
View patch
sierra_wirelesspatch availablevia llm_extracted
Fixed in: 7.23.1
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: java-1.4.2-ibm-sap
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: nss
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openssl
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: nss
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: java-1.5.0-ibm
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: gnutls
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openssl098e
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: gnutls
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: nss
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: openssl
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: openssl096b
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: gnutls
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: openssl097a

Vendor Advisories (3)

sierra_wirelessllm-sierra_wireless-7a5e5aff105c6d22HIGH

SSL CBC IV vulnerability

Jan 24, 2012
jitsillm-jitsi-7314354e06cb9555HIGH

SSL CBC IV vulnerability

Jan 24, 2012
redhatCVE-2011-3389Moderate

HTTPS: block-wise chosen-plaintext attack against SSL/TLS (BEAST)

Sep 10, 2011

References

blog.mozilla.com / security/2011/09/27/attack-against-tls-protected-communications
Third Party Advisory
blogs.technet.com / b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx
Third Party Advisory
blogs.technet.com / b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx
Third Party Advisory
curl.haxx.se / docs/adv_20120124B.html
Third Party Advisory
downloads.asterisk.org / pub/security/AST-2016-001.html
Third Party Advisory
ekoparty.org / 2011/juliano-rizzo.php
Broken Link
eprint.iacr.org / 2004/111
Third Party Advisory
eprint.iacr.org / 2006/136
Third Party Advisory
googlechromereleases.blogspot.com / 2011/10/chrome-stable-release.html
Not ApplicableVendor Advisory
isc.sans.edu / diary/SSL+TLS+part+3+/11635
Third Party Advisory
lists.apple.com / archives/Security-announce/2011//Oct/msg00001.html
Broken Link
lists.apple.com / archives/Security-announce/2011//Oct/msg00002.html
Broken Link
lists.apple.com / archives/security-announce/2012/Feb/msg00000.html
Broken LinkMailing List
lists.apple.com / archives/security-announce/2012/Jul/msg00001.html
Broken LinkMailing List
lists.apple.com / archives/security-announce/2012/May/msg00001.html
Broken LinkMailing List
lists.apple.com / archives/security-announce/2012/Sep/msg00004.html
Broken LinkMailing List
lists.apple.com / archives/security-announce/2013/Oct/msg00004.html
Broken LinkMailing List
lists.opensuse.org / opensuse-security-announce/2012-01/msg00049.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2012-01/msg00051.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2012-05/msg00009.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2020-01/msg00040.html
Broken Link
marc.info
Issue TrackingMailing ListThird Party Advisory
marc.info
Issue TrackingMailing ListThird Party Advisory
marc.info
Issue TrackingMailing ListThird Party Advisory
marc.info
Issue TrackingMailing ListThird Party Advisory
marc.info
Issue TrackingMailing ListThird Party Advisory
marc.info
Issue TrackingMailing ListThird Party Advisory
my.opera.com / securitygroup/blog/2011/09/28/the-beast-ssl-tls-issue
Third Party Advisory
osvdb.org / 74829
Broken Link
rhn.redhat.com / errata/RHSA-2012-0508.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2013-1455.html
Broken Link
blogs.oracle.com / sunsecurity/entry/multiple_vulnerabilities_in_fetchmail
Third Party Advisory
bugzilla.novell.com / show_bug.cgi
Issue TrackingThird Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
cert-portal.siemens.com / productcert/pdf/ssa-556833.pdf
Third Party Advisory
docs.microsoft.com / en-us/security-updates/securitybulletins/2012/ms12-006
PatchVendor Advisory
secunia.com / advisories/45791
Not Applicable
secunia.com / advisories/47998
Not Applicable
secunia.com / advisories/48256
Not Applicable
secunia.com / advisories/48692
Not Applicable
secunia.com / advisories/48915
Not Applicable
secunia.com / advisories/48948
Not Applicable
secunia.com / advisories/49198
Not Applicable
secunia.com / advisories/55322
Not Applicable
secunia.com / advisories/55350
Not Applicable
secunia.com / advisories/55351
Not Applicable
security.gentoo.org / glsa/glsa-201203-02.xml
Third Party Advisory
security.gentoo.org / glsa/glsa-201406-32.xml
Third Party Advisory
h20564.www2.hp.com / portal/site/hpsc/public/kb/docDisplay
Broken Link
hermes.opensuse.org / messages/13154861
Broken Link
hermes.opensuse.org / messages/13155432
Broken Link
ics-cert.us-cert.gov / advisories/ICSMA-18-058-02
Third Party AdvisoryUS Government Resource
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14752
Third Party Advisory
support.apple.com / kb/HT4999
Third Party Advisory
support.apple.com / kb/HT5001
Third Party Advisory
support.apple.com / kb/HT5130
Third Party Advisory
support.apple.com / kb/HT5281
Broken Link
support.apple.com / kb/HT5501
Third Party Advisory
support.apple.com / kb/HT6150
Third Party Advisory
technet.microsoft.com / security/advisory/2588513
PatchVendor Advisory
vnhacker.blogspot.com / 2011/09/beast.html
Third Party Advisory
apcmedia.com / salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf
Third Party Advisory
debian.org / security/2012/dsa-2398
Third Party Advisory
educatedguesswork.org / 2011/09/security_impact_of_the_rizzodu.html
Broken Link
ibm.com / developerworks/java/jdk/alerts
Third Party Advisory
imperialviolet.org / 2011/09/23/chromeandbeast.html
Third Party Advisory
insecure.cl / Beast-SSL.rar
Broken LinkPatch
kb.cert.org / vuls/id/864643
Third Party AdvisoryUS Government Resource
mandriva.com / security/advisories
Broken Link
opera.com / docs/changelogs/mac/1151
Third Party Advisory
opera.com / docs/changelogs/mac/1160
Third Party Advisory
opera.com / docs/changelogs/unix/1151
Third Party Advisory
opera.com / docs/changelogs/unix/1160
Third Party Advisory
opera.com / docs/changelogs/windows/1151
Third Party Advisory
opera.com / docs/changelogs/windows/1160
Third Party Advisory
opera.com / support/kb/view/1004
Third Party AdvisoryVendor Advisory
oracle.com / technetwork/topics/security/cpujan2015-1972971.html
Third Party Advisory
oracle.com / technetwork/topics/security/cpujul2015-2367936.html
Third Party Advisory
oracle.com / technetwork/topics/security/javacpuoct2011-443431.html
Third Party Advisory
redhat.com / support/errata/RHSA-2011-1384.html
Third Party AdvisoryVendor Advisory
redhat.com / support/errata/RHSA-2012-0006.html
Third Party Advisory
securityfocus.com / bid/49388
Third Party AdvisoryVDB Entry
securityfocus.com / bid/49778
Third Party AdvisoryVDB Entry
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1029190
Broken LinkThird Party AdvisoryVDB Entry
ubuntu.com / usn/USN-1263-1
Third Party Advisory
us-cert.gov / cas/techalerts/TA12-010A.html
Third Party AdvisoryUS Government Resource