CVE-2011-4354 describes a critical vulnerability in OpenSSL versions prior to 0.9.8h, specifically affecting 32-bit platforms when using ECDH or ECDHE cipher suites. An incorrect modular reduction algorithm in the P-256 and P-384 NIST elliptic curve implementations allows remote attackers to deduce a TLS server's private key through multiple handshake attempts. This vulnerability carries a CVSS score of 5.8, indicating a medium severity with network access, medium attack complexity, and potential for partial confidentiality and integrity compromise. Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.8gCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:x86:* | ||
0.9.1cCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.1c:*:*:*:*:*:x86:* | ||
0.9.2bCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.2b:*:*:*:*:*:x86:* | ||
0.9.3CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.3:*:*:*:*:*:x86:* | ||
0.9.3aCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.3a:*:*:*:*:*:x86:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.