Executive Summary

Informations
Name CVE-2011-1923 First vendor Publication 2012-06-20
Vendor Cve Last vendor Modification 2013-10-24

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:H/Au:N/C:P/I:P/A:N)
Cvss Base Score 4 Attack Range Network
Cvss Impact Score 4.9 Attack Complexity High
Cvss Expoit Score 4.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

The Diffie-Hellman key-exchange implementation in dhm.c in PolarSSL before 0.14.2 does not properly validate a public parameter, which makes it easier for man-in-the-middle attackers to obtain the shared secret key by modifying network traffic, a related issue to CVE-2011-5095.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1923

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-310 Cryptographic Issues

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 9

Nessus® Vulnerability Scanner

Date Description
2013-10-18 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201310-10.nasl - Type : ACT_GATHER_INFO
2011-04-11 Name : The remote SSL/TLS server accepts a weak Diffie-Hellman public value.
File : polarssl_dh_vuln.nasl - Type : ACT_ATTACK

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/46670
CONFIRM http://polarssl.org/trac/wiki/SecurityAdvisory201101
MISC http://www.cl.cam.ac.uk/~rja14/Papers/psandqs.pdf
http://www.nessus.org/plugins/index.php?view=single&id=53360

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
Date Informations
2021-05-05 01:08:23
  • Multiple Updates
2021-05-04 12:14:29
  • Multiple Updates
2021-04-22 01:15:46
  • Multiple Updates
2020-05-23 01:44:30
  • Multiple Updates
2020-05-23 00:28:32
  • Multiple Updates
2016-04-26 20:45:51
  • Multiple Updates
2014-02-17 11:02:25
  • Multiple Updates
2013-10-24 13:21:47
  • Multiple Updates
2013-05-10 23:00:40
  • Multiple Updates