UNKNOWN OpenStack PoC
CVE-2015-0204
OSSN-0045: = Vulnerable clients allow a TLS protocol downgrade (FREAK)=
Some client-side libraries, including un-patched versions of OpenSSL,
contain a vulnerability which can allow a man-in-the-middle (MITM) to
force a TLS version downgrade. Even though this vulnerability exists in
the client side, an attack known as FREAK is exploitable when TLS
servers offer weak cipher choices. This security note provides guidance
to mitigate the FREAK attack on the server side, so that TLS provides
reasonable security for even un-patched clients.
Affected Products
- OpenStack services
- OpenStack clients
- Web servers (Apache, Nginx, etc)
- SSL/TLS terminators (Stud, Pound, etc)
- Proxy services (HAProxy, etc)
- Miscellaneous services (eventlet, syslog, ldap, smtp, etc)
- CVE-2015-0204
References
This unknown severity vulnerability was published on 2026-08-27 via OpenStack. 🚨 A public proof-of-concept exploit is available on GitHub. EPSS score: 98.7% (top 0% of all CVEs by exploitation probability). Affected: OpenStack services, OpenStack clients, Web servers (Apache, Nginx, etc) and 4 more.
vulnfeed aggregates 11337 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.