CVE-2015-3152, dubbed the "BACKRONYM" attack, affects Oracle MySQL (before 5.7.3), Oracle MySQL Connector/C (before 6.1.3), and MariaDB (before 5.5.44). The vulnerability stems from the --ssl option being interpreted as optional, enabling man-in-the-middle attackers to spoof servers through a cleartext-downgrade attack. This medium-severity flaw (CVSS 5.9) has a high impact on integrity, requiring high attack complexity, but no user interaction. While not listed in KEV or having public exploit code, it garnered significant community discussion and media coverage at the time of its discovery.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.7.2CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
<= 6.1.2CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_connector\/c:*:*:*:*:*:*:*:* | ||
>= 5.5.0, < 5.5.44CPE matchmatch criteria | cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* | ||
>= 10.0.0, < 10.0.20CPE matchmatch criteria | cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* | ||
21CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.