CVE-2010-4180

medium F5
CVSS v3 Base Score
4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS Score
3.8%
Exploitation probability in 30 days
Top 12% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
M
Confidentiality
None
Integrity
P
Availability
None
Published: December 6, 2010 (5637 days ago)
Last Modified: April 29, 2026
Vendor: F5
Source: NVD

Description

OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.

CWE

NVD-CWE-noinfo

Affected Products

openssl opensslfedoraproject fedoradebian debian linuxcanonical ubuntu linuxopensuse opensusesuse linux enterprisesuse linux enterprise desktopsuse linux enterprise serverf5 nginx

References