CVE Feed

    Dashboard / CVE / CVE-2015-4000

    CVE-2015-4000

    The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

    Published:May 20, 2015
    Last Modified:May 27, 2026
    EPS:May 21, 2015
    EPSS Score:0.93743
    CVSS Score:3.7

    Affected Products

    Vendor
    Apple
    Product
    Iphone Os
    Vendor
    Apple
    Product
    Mac Os X
    Vendor
    Apple
    Product
    Safari
    Vendor
    Canonical
    Product
    Ubuntu Linux
    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Google
    Product
    Chrome
    Vendor
    Hp
    Product
    Hp-ux
    Vendor
    Ibm
    Product
    Content Manager
    Vendor
    Microsoft
    Product
    Internet Explorer
    Vendor
    Mozilla
    Product
    Firefox
    Vendor
    Mozilla
    Product
    Firefox Esr
    Vendor
    Mozilla
    Product
    Firefox Os
    Vendor
    Mozilla
    Product
    Network Security Services
    Vendor
    Mozilla
    Product
    Seamonkey
    Vendor
    Mozilla
    Product
    Thunderbird
    Vendor
    Openssl
    Product
    Openssl
    Vendor
    Opera
    Product
    Opera Browser
    Vendor
    Oracle
    Product
    Jdk
    Vendor
    Oracle
    Product
    Jre
    Vendor
    Oracle
    Product
    Jrockit
    Vendor
    Oracle
    Product
    Sparc-opl Service Processor
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Jboss Enterprise Application Platform
    Vendor
    Redhat
    Product
    Jboss Enterprise Web Server
    Vendor
    Redhat
    Product
    Network Satellite
    Vendor
    Redhat
    Product
    Rhel Extras
    Vendor
    Redhat
    Product
    Rhel Extras Oracle Java
    Vendor
    Suse
    Product
    Linux Enterprise Desktop
    Vendor
    Suse
    Product
    Linux Enterprise Server
    Vendor
    Suse
    Product
    Linux Enterprise Software Development Kit
    Vendor
    Suse
    Product
    Suse Linux Enterprise Server

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High