CVE-2011-5095 describes a vulnerability in OpenSSL versions 0.9.8 when FIPS mode is enabled, specifically within its Diffie-Hellman key-exchange implementation. The flaw lies in the improper validation of a public parameter, making it susceptible to man-in-the-middle attacks. This vulnerability has a CVSS score of 4.0, indicating a medium attack complexity and partial confidentiality and integrity impact, with no availability impact. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.8CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.