CVE-2015-1788 describes a denial-of-service vulnerability in OpenSSL versions prior to 0.9.8s, 1.0.0e, 1.0.1n, and 1.0.2b. Specifically, the BN_GF2m_mod_inv function can enter an infinite loop when processing malformed ECParameters structures in Elliptic Curve algorithms. This vulnerability has a CVSS score of 4.3, indicating a medium severity, and allows remote attackers to cause a denial of service with medium attack complexity. While the FAUCET Risk Score is high at 84/100, there is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in the KEV catalog. Despite this, community discussion and media coverage suggest a notable level of attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.8zfCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0:beta1:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0:beta2:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0:beta3:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.