Downgrade Attack Vulnerability in EMC RSA BSAFE Products
CVE-2015-0533
7.5HIGH
What is CVE-2015-0533?
EMC RSA BSAFE Micro Edition Suite versions 4.0.x prior to 4.0.8 and 4.1.x prior to 4.1.3, as well as RSA BSAFE SSL-C version 2.8.9 and earlier, contain a vulnerability that allows remote SSL servers to carry out ECDHE-to-ECDH downgrade attacks. This can result in the loss of forward secrecy by omitting the crucial ServerKeyExchange message, leaving encrypted communications susceptible to interception. This issue is similar to previous vulnerabilities and highlights the need for robust security practices when managing encryption protocols.