openssl mitm downgrade attack
Published Oct 18, 2005
5.0
MEDIUMCVSS 2.0
EPSS 4.87%
Description
The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.
Affected products
No data.
- 0.9.7
- 0.9.7a
- 0.9.7b
- 0.9.7c
- 0.9.7d
- 0.9.7e
- 0.9.7f
- 0.9.7g
- 0.9.8
No data.
Red Hat Enterprise Linux 3
openssl-0:0.9.7a-33.17
Fixed · RHSA-2005:800
Red Hat Enterprise Linux 3
openssl096b-0:0.9.6b-16.22.4
Fixed · RHSA-2005:800
Red Hat Enterprise Linux 4
openssl-0:0.9.7a-43.4
Fixed · RHSA-2005:800
Red Hat Enterprise Linux 4
openssl096b-0:0.9.6b-22.4
Fixed · RHSA-2005:800
Red Hat Network Satellite Server v 4.2
rhn-solaris-bootstrap-0:5.0.2-3
Fixed · RHSA-2008:0525
Red Hat Network Satellite Server v 4.2
rhn_solaris_bootstrap_5_0_2_3-0:1-0
Fixed · RHSA-2008:0525
Red Hat Network Satellite Server v 4.2 (RHEL3)
rhn-solaris-bootstrap-0:5.0.2-3
Fixed · RHSA-2008:0525
Red Hat Network Satellite Server v 4.2 (RHEL3)
rhn_solaris_bootstrap_5_0_2_3-0:1-0
Fixed · RHSA-2008:0525
Red Hat Network Satellite Server v 5.0
rhn-solaris-bootstrap-0:5.0.2-3
Fixed · RHSA-2008:0264
Red Hat Network Satellite Server v 5.0
rhn_solaris_bootstrap_5_0_2_3-0:1-0
Fixed · RHSA-2008:0264
Red Hat Network Satellite Server v 5.1
rhn-solaris-bootstrap-0:5.1.1-3
Fixed · RHSA-2008:0629
Red Hat Network Satellite Server v 5.1
rhn_solaris_bootstrap_5_1_1_3-0:1-0
Fixed · RHSA-2008:0629
Red Hat Stronghold 4
n/a
Fixed · RHSA-2005:882
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | openssl-0:0.9.7a-33.17 | Fixed | RHSA-2005:800 |
| Red Hat Enterprise Linux 3 | openssl096b-0:0.9.6b-16.22.4 | Fixed | RHSA-2005:800 |
| Red Hat Enterprise Linux 4 | openssl-0:0.9.7a-43.4 | Fixed | RHSA-2005:800 |
| Red Hat Enterprise Linux 4 | openssl096b-0:0.9.6b-22.4 | Fixed | RHSA-2005:800 |
| Red Hat Network Satellite Server v 4.2 | rhn-solaris-bootstrap-0:5.0.2-3 | Fixed | RHSA-2008:0525 |
| Red Hat Network Satellite Server v 4.2 | rhn_solaris_bootstrap_5_0_2_3-0:1-0 | Fixed | RHSA-2008:0525 |
| Red Hat Network Satellite Server v 4.2 (RHEL3) | rhn-solaris-bootstrap-0:5.0.2-3 | Fixed | RHSA-2008:0525 |
| Red Hat Network Satellite Server v 4.2 (RHEL3) | rhn_solaris_bootstrap_5_0_2_3-0:1-0 | Fixed | RHSA-2008:0525 |
| Red Hat Network Satellite Server v 5.0 | rhn-solaris-bootstrap-0:5.0.2-3 | Fixed | RHSA-2008:0264 |
| Red Hat Network Satellite Server v 5.0 | rhn_solaris_bootstrap_5_0_2_3-0:1-0 | Fixed | RHSA-2008:0264 |
| Red Hat Network Satellite Server v 5.1 | rhn-solaris-bootstrap-0:5.1.1-3 | Fixed | RHSA-2008:0629 |
| Red Hat Network Satellite Server v 5.1 | rhn_solaris_bootstrap_5_1_1_3-0:1-0 | Fixed | RHSA-2008:0629 |
| Red Hat Stronghold 4 | n/a | Fixed | RHSA-2005:882 |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.87% (0.04866) | 91.77th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.87% (0.04866) | 90.88th | v5 (v2026.06.15) |
| Aug 20, 2025 | 10.23% (0.10231) | 92.83th | v4 (v2025.03.14) |
| Mar 30, 2025 | 8.92% (0.08921) | 91.77th | v4 (v2025.03.14) |
| Mar 29, 2025 | 20.05% (0.20048) | 92.63th | v4 (v2025.03.14) |
| Mar 17, 2025 | 8.92% (0.08921) | 91.95th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.07% (0.01068) | 84.84th | v3 (v2023.03.01) |
| May 3, 2024 | 1.26% (0.01259) | 85.49th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.26% (0.01259) | 83.44th | v3 (v2023.03.01) |
| Mar 6, 2023 | 15.26% (0.15261) | 95.93th | v2 (v2022.01.01) |
| Feb 13, 2023 | 15.26% (0.15261) | 95.78th | v2 (v2022.01.01) |
| Feb 3, 2023 | 9.84% (0.09837) | 94.14th | v2 (v2022.01.01) |
| Apr 1, 2022 | 15.26% (0.15261) | 95.56th | v2 (v2022.01.01) |
| Feb 4, 2022 | 15.26% (0.15261) | 91.34th | v2 (v2022.01.01) |
No CWE recorded.
References (78)
- ftp://ftp.software.ibm.com/pc/pccbbs/pc_servers/dir5.10.3_docs_relnotes.pdf x_refsource_MISC
- http://docs.info.apple.com/article.html?artnum=302847 vendor-advisoryx_refsource_APPLE
- http://itrc.hp.com/service/cki/docDisplay.do?docId=c00805100 vendor-advisoryx_refsource_HP
- http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540 vendor-advisoryx_refsource_HP
- http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html vendor-advisoryx_refsource_TRUSTIX
- http://secunia.com/advisories/17146 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17151 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17153 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17169 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17178 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17180 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17189 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17191 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17210 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17259 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17288 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17335 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17344 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17389 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17409 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17432 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17466 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17589 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17617 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17632 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17813 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17888 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18045 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18123 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18165 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18663 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19185 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21827 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23280 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23340 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23843 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23915 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25973 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26893 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31492 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1015032 vdb-entryx_refsource_SECTRACK
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101974-1 vendor-advisoryx_refsource_SUNALERT
- http://support.avaya.com/elmodocs2/security/ASA-2006-031.htm x_refsource_CONFIRM
- http://support.avaya.com/elmodocs2/security/ASA-2006-260.htm x_refsource_CONFIRM
- http://www-1.ibm.com/support/docview.wss?uid=isg1SSRVHMCHMC_C081516_754 x_refsource_MISC
- http://www.cisco.com/warp/public/707/cisco-response-20051202-openssl.shtml vendor-advisoryx_refsource_CISCO
- http://www.debian.org/security/2005/dsa-875 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2005/dsa-881 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2005/dsa-882 vendor-advisoryx_refsource_DEBIAN
- http://www.hitachi-support.com/security_e/vuls_e/HS06-022_e/01-e.html x_refsource_CONFIRM
- http://www.hitachi-support.com/security_e/vuls_e/HS07-016_e/index-e.html x_refsource_CONFIRM
- http://www.juniper.net/support/security/alerts/PSN-2005-12-025.txt x_refsource_MISC
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:179 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2005_61_openssl.html vendor-advisoryx_refsource_SUSE
- http://www.openssl.org/news/secadv_20051011.txt x_refsource_CONFIRMPatchVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-762.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2005-800.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0629.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/15071 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/15647 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/24799 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2005/2036 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2005/2659 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2005/2710 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2005/2908 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2005/3002 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2005/3056 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2006/3531 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/0326 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/0343 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/2457 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2005-2969 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=430660 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35287 vdb-entryx_refsource_XF
- https://issues.rpath.com/browse/RPL-1633 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2005-2969
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11454 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2005-2969
Change history (0)
No recorded changes yet.