- Contains Software Flaws (CVE)
- CPE Product Version: cpe:/a:mozilla:seamonkey:2.35
There are 1 matching records.
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
May 20, 2015; 08:59:00 PM -04:00
V3: 3.7 LOW
V2: 4.3 MEDIUM