CVE-2015-0205 describes a vulnerability in OpenSSL versions 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k, where the ssl3_get_cert_verify function incorrectly handles client authentication with Diffie-Hellman (DH) certificates. This flaw allows remote attackers to bypass authentication and gain unauthorized access to a server configured to recognize a DH-supporting Certification Authority, without needing the private key. The vulnerability has a CVSS score of 5.0 (Medium), indicating a network attack vector with low complexity and a partial integrity impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0aCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:* | ||
1.0.0bCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:* | ||
1.0.0cCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0c:*:*:*:*:*:*:* | ||
1.0.0dCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0d:*:*:*:*:*:*:* | ||
1.0.0eCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0e:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.