CVE-1999-0428

CVSS 2.0 Score 7.5 of 10 (high)

Details

Published Mar 22, 1999
Updated: Nov 20, 2024
CWE ID 384

Summary

CVE-1999-0428 is a vulnerability affecting OpenSSL and SSLeay, two popular cryptographic libraries. This issue enables remote attackers to reuse SSL sessions, thereby bypassing access controls. Attackers can exploit this flaw to gain unauthorized access to systems and data protected by these libraries. The vulnerability could lead to significant security risks, as SSL sessions are used to secure communications between servers and clients. Organizations using affected versions of OpenSSL and SSLeay should apply the available patches as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • OpenSSL

Affected Vendors

  • The OpenSSL Project