AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2010-4180

MEDIUM · CVSS 4.3 EPSS 9.50%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2010-12-06 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2010-4180
Severity
MEDIUM
CVSS
4.3
EPSS
9.50%
OpenSSL

Original NVD Description

OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.