CVE-2015-0204, known as "FREAK," is a critical vulnerability in OpenSSL client code (versions before 0.9.8zd, 1.0.0p, and 1.0.1k) that allows remote SSL servers to force a downgrade to weak EXPORT_RSA ciphers. This enables brute-force decryption of encrypted communications. The vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and potential for partial integrity impact, but no confidentiality or availability impact. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it garnered significant community discussion and media coverage at the time of its discovery, highlighting its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.8zcCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
1.0.0aCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:* | ||
1.0.0bCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:* | ||
1.0.0cCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0c:*:*:*:*:*:*:* | ||
1.0.0dCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0d:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.