2.1
CVSSv2

CVE-2020-12872

Published: 15/05/2020 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

yaws_config.erl in Yaws up to and including 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if running on an Erlang/OTP virtual machine with a version less than 21.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

yaws yaws

Vendor Advisories

Debian Bug report logs - #961422 yaws: CVE-2020-12872 Package: src:yaws; Maintainer for src:yaws is Debian Erlang Packagers <pkg-erlang-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 24 May 2020 13:09:01 UTC Severity: important Tags: security, upstream Found in versi ...
yaws_configerl in Yaws through 207 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks ...