AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2015-2091

MEDIUM · CVSS 5 EPSS 3.25%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-03-13 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.0. It may be remotely exploitable.

CVE
CVE-2015-2091
Severity
MEDIUM
CVSS
5
EPSS
3.25%

Original NVD Description

The authentication hook (mgs_hook_authz) in mod-gnutls 0.5.10 and earlier does not validate client certificates when "GnuTLSClientVerify require" is set, which allows remote attackers to spoof clients via a crafted certificate.