Mono SSLv2 Fallback CVE-2015-2320 Man in the Middle Security Bypass Vulnerability
BID:73256
CVE-2015-2320 |Info
Mono SSLv2 Fallback CVE-2015-2320 Man in the Middle Security Bypass Vulnerability
| Bugtraq ID: | 73256 |
| Class: | Design Error |
| CVE: |
CVE-2015-2320 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2015 12:00AM |
| Updated: | Mar 17 2015 12:00AM |
| Credit: | Inria |
| Vulnerable: |
Mono Mono 2.8.2 Mono Mono 2.8.1 Mono Mono 2.8.1 Mono Mono 2.6.4 Mono Mono 2.4.2 Mono Mono 2.0 Mono Mono 2.8 |
| Not Vulnerable: | |
Discussion
Mono SSLv2 Fallback CVE-2015-2320 Man in the Middle Security Bypass Vulnerability
Mono is prone to a security-bypass vulnerability due to an error in the TLS state machine.
An attacker can exploit this issue to intercept and decrypt the encrypted traffic by conducting a man-in-the-middle attack. This may lead to other attacks.
Mono is prone to a security-bypass vulnerability due to an error in the TLS state machine.
An attacker can exploit this issue to intercept and decrypt the encrypted traffic by conducting a man-in-the-middle attack. This may lead to other attacks.
Exploit / POC
Mono SSLv2 Fallback CVE-2015-2320 Man in the Middle Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Mono SSLv2 Fallback CVE-2015-2320 Man in the Middle Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Mono SSLv2 Fallback CVE-2015-2320 Man in the Middle Security Bypass Vulnerability
References:
References: