CVE-1999-0428 describes a vulnerability in OpenSSL and SSLeay that allows remote attackers to reuse SSL sessions, potentially bypassing access controls. This high-severity vulnerability (CVSS 7.5) is easily exploitable over the network with no authentication required, leading to potential compromise of confidentiality, integrity, and availability. Despite its age and severity, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9.2bCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-1999-0428
Sep 8, 2020OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.
Jan 2, 2000openssl: allow remote attackers to reuse SSL sessions and bypass access controls
Mar 22, 1999