AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-0654

MEDIUM · CVSS 5.1 EPSS 2.12%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-02-20 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2009-0654
Severity
MEDIUM
CVSS
5.1
EPSS
2.12%

Original NVD Description

Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit router, to confirm that a sender and receiver are communicating via vectors involving (1) replaying, (2) modifying, (3) inserting, or (4) deleting a single cell, and then observing cell recognition errors at the exit router. NOTE: the vendor disputes the significance of this issue, noting that the product's design "accepted end-to-end correlation as an attack that is too expensive to solve."