CVE-2015-4000: Low severity OpenSSL OpenSSL vulnerability

Published May 20, 2015
·
Updated

Last updated 24 July 2024

Other sources

The TLS protocol 1.2 and earlier, when a DHEEXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHEEXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHEEXPORT and then rewriting a ServerHello with DHEEXPORT replaced by DHE, aka the "Logjam" issue.

Launchpad

TLS connections using Diffie-Hellman key exchange protocol were found to be vulnerable to an attack, in which a man-in-the-middle attacker could downgrade vulnerable TLS connections to 512-bit export-grade cryptography. The attack affects any server that supports DHEEXPORT ciphers. This attack can be conduted by precomputation on the 512 bit primes given in two popular sets of weak Diffie-Hellman parameters, namely Apache 2.1.5 - 2.4.7 and OpenSSL.

The following attack scenarios are possible:

1. Offline Decryption of Weak DHE Connections: This attack requires that the server default to using a Diffie-Hellman key exchange with 512-bit parameters. In this attack, there is a passive network adversary able to eavesdrop, who can obtain a transcript of the communication between the client and server.

2. DHEEXPORT Downgrade and Offline Decryption of TLS False Start: This attack only requires that a server support 512-bit parameters, but has a greater requirement of the client and attacker. The server, in this case, only needs to support DHEEXPORT cipher suites or use 512-bit parameters in non-export DHE ciphers. The client must be using the TLS False Start extension.

3. DHEEXPORT Downgrade and Man-In-The-Middle Server Impersonation: This is similar to the second attack, but does not need TLS False Start extension to be enabled. We instead require the client be willing to wait a significant amount of time for the handshake to complete. This is because the attacker must compute the connection key during the handshake process, but computing the key takes several minutes.

External Reference:

https://weakdh.org/ https://access.redhat.com/articles/1456263

Affected Software

48 affected componentsFixes available
OpenSSL OpenSSL>=1.0.1<=1.0.1m
OpenSSL OpenSSL>=1.0.2<=1.0.2a
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=14.10
Canonical Ubuntu Linux=15.04
All of the following
OpenSSL OpenSSL<=1.0.1m
HP HP-UX=b.11.31
IBM Content Manager Enterprise=8.5
Oracle Jrockit=r28.3.6
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Oracle JDK=1.6.0-update95
Oracle JDK=1.7.0-update75
Oracle JDK=1.7.0-update80
Oracle JDK=1.8.0-update_33
Oracle JDK=1.8.0-update45
Oracle JRE=1.6.0-update_95
Oracle JRE=1.7.0-update_75
Oracle JRE=1.7.0-update_80
Oracle JRE=1.8.0-update_33
Oracle JRE=1.8.0-update_45
SUSE Linux Enterprise Desktop=12
SUSE Linux Enterprise Server=11.0-sp4
SUSE Linux Enterprise Software Development Kit=12
SUSE SUSE Linux Enterprise Server=12
Apple iPhone OS<=8.3
Apple iOS and macOS<=10.10.3
Mozilla Network Security Services=3.19
Oracle Sparc-opl Service Processor<=1121
Apple Safari
Google Chrome
Microsoft Internet Explorer
Mozilla Firefox
Opera Opera Browser
Mozilla Firefox=38.1.0
Mozilla Firefox=39.0
Mozilla Firefox ESR=31.8
Mozilla SeaMonkey=2.35
Mozilla Thunderbird=31.8
Mozilla Thunderbird=38.1
Mozilla Firefox OS=2.2
OpenSSL OpenSSL<=1.0.1m
HP HP-UX=b.11.31
Mozilla Firefox ESR=38.1.0
debian/nss
2:3.61-1+deb11u32:3.61-1+deb11u42:3.87.1-1+deb12u12:3.110-1
debian/openjdk-8
8u452-ga-1
debian/openssl
1.1.1w-0+deb11u11.1.1w-0+deb11u23.0.15-1~deb12u13.0.14-1~deb12u23.5.0-1

Event History

May 20, 2015
Data Sourced
06:26 AM
DescriptionSeverityAffected Software
May 21, 2015
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:09 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:08 AM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2015-4000?

CVE-2015-4000 is classified as a medium severity vulnerability due to its potential for man-in-the-middle attacks.

2

How do I fix CVE-2015-4000?

To fix CVE-2015-4000, disable DHE_EXPORT ciphersuites or upgrade to a version of the affected software that does not allow such ciphers.

3

What software is affected by CVE-2015-4000?

CVE-2015-4000 affects multiple software packages including OpenSSL, NSS, and various versions of Oracle JDK and Debian Linux.

4

What type of attack does CVE-2015-4000 enable?

CVE-2015-4000 enables man-in-the-middle attacks through cipher-downgrade vulnerabilities.

5

Is CVE-2015-4000 still a concern in modern systems?

CVE-2015-4000 remains a concern in modern systems that use outdated libraries or configurations allowing DHE_EXPORT ciphers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203