CVE-2016-2850
—CVSS 3.0
7.5 high
EPSS
2%p81
Published
()
Modified
Description
Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors.
- Vendors
- fedoraprojectbotan project
- Products
- fedora, botan
- Weakness
- CWE-20
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.