Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-1791

24
FAUCET Score

CVE-2015-1791 is a race condition in OpenSSL's ssl3_get_new_session_ticket function, affecting versions before 0.9.8zg, 1.0.0s, 1.0.1n, and 1.0.2b. This flaw, triggered in multi-threaded clients by specific NewSessionTicket interactions, can lead to a denial of service through a double free and application crash, with potential for other unspecified impacts. Rated with a CVSS score of 6.8, it is a network-attackable vulnerability with medium complexity, posing partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, no known exploit code (Metasploit, Nuclei, ExploitDB), and it has received limited community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.9.8zfCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0:beta1:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0:beta2:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0:beta3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.8MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
15.97%
Probability of exploitation in next 30 days
EPSS Percentile
96.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1597 is in the 97th percentile among its peer group of 19,956 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openssl-0:1.0.1e-30.el6_6.11
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssl-1:1.0.1e-42.ael7b_1.8
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openssl098e
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssl098e
redhatend of lifevia redhat_api
Product: Red Hat JBoss Enterprise Web Server 1Fixed in: openssl

Vendor Advisories (1)

redhatCVE-2015-1791Low

OpenSSL: Race condition handling NewSessionTicket

Jun 11, 2015

References

fortiguard.com / advisory/openssl-vulnerabilities-june-2015
ftp.netbsd.org / pub/NetBSD/security/advisories/NetBSD-SA2015-008.txt.asc
kb.juniper.net / InfoCenter/index
kb.juniper.net / InfoCenter/index
lists.apple.com / archives/security-announce/2015/Aug/msg00001.html
lists.fedoraproject.org / pipermail/package-announce/2015-June/160436.html
lists.fedoraproject.org / pipermail/package-announce/2015-June/160647.html
lists.opensuse.org / opensuse-security-announce/2015-06/msg00023.html
lists.opensuse.org / opensuse-security-announce/2015-06/msg00024.html
lists.opensuse.org / opensuse-security-announce/2015-06/msg00026.html
lists.opensuse.org / opensuse-security-announce/2015-07/msg00004.html
lists.opensuse.org / opensuse-security-announce/2015-07/msg00006.html
lists.opensuse.org / opensuse-security-announce/2015-07/msg00007.html
lists.opensuse.org / opensuse-security-announce/2016-03/msg00011.html
marc.info
marc.info
rhn.redhat.com / errata/RHSA-2015-1115.html
bto.bluecoat.com / security-advisory/sa98
cert-portal.siemens.com / productcert/pdf/ssa-412672.pdf
github.com / openssl/openssl/commit/98ece4eebfb6cd45cc8d550c6ac0022965071afc
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
kc.mcafee.com / corporate/index
openssl.org / news/secadv/20150611.txt
security.gentoo.org / glsa/201506-02
support.apple.com / kb/HT205031
support.citrix.com / article/CTX216642
arista.com / en/support/advisories-notices/security-advisories/1144-security-advisory-11
openssl.org / news/secadv_20150611.txt
Vendor Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-20150612-openssl
www-304.ibm.com / support/docview.wss
debian.org / security/2015/dsa-3287
fortiguard.com / advisory/2015-06-11-fortinet-vulnerability-openssl-vulnerabilities-june-2015
fortiguard.com / advisory/openssl-vulnerabilities-june-2015
oracle.com / technetwork/security-advisory/cpujul2016-2881720.html
oracle.com / technetwork/security-advisory/cpujul2017-3236622.html
oracle.com / technetwork/security-advisory/cpuoct2016-2881722.html
oracle.com / technetwork/security-advisory/cpuoct2017-3236626.html
oracle.com / technetwork/topics/security/bulletinjul2015-2511963.html
oracle.com / technetwork/topics/security/cpujan2016-2367955.html
oracle.com / technetwork/topics/security/cpuoct2015-2367953.html
securityfocus.com / bid/75161
securityfocus.com / bid/91787
securitytracker.com / id/1032479
ubuntu.com / usn/USN-2639-1