CVE-2015-3193 describes a critical vulnerability in the Montgomery squaring implementation within OpenSSL 1.0.2 before 1.0.2e on x86_64 platforms, specifically affecting the BN_mod_exp function. This flaw, due to mishandled carry propagation, produces incorrect output, making it easier for remote attackers to extract sensitive private-key information from Diffie-Hellman (DH) or Diffie-Hellman Ephemeral (DHE) ciphersuites. Rated with a CVSS score of 7.5 (High), this vulnerability has a low attack complexity and requires no user interaction, allowing for high confidentiality impact. Its FAUCET Risk Score of 94/100 further highlights its severity. While there is no evidence of active exploitation (not in KEV) and no public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention with 5 mentions and 5 media articles, indicating widespread awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.2CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:* | ||
1.0.2aCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.2a:*:*:*:*:*:*:* | ||
1.0.2bCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.2b:*:*:*:*:*:*:* | ||
1.0.2cCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.2c:*:*:*:*:*:*:* | ||
1.0.2dCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.2d:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.