CVE-2015-4000 - CVE House
Back to Database
Status published Unknown CVE-2015-4000

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite...

Vulnerability Description

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-4000

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

openssl, ubuntu linux, hp-ux, content manager, jrockit, debian linux, jdk, jre, linux enterprise desktop, linux enterprise server, linux enterprise software development kit, suse linux enterprise server, iphone os, mac os x, network security services, sparc-opl service processor, safari, chrome, internet explorer, firefox, opera browser, firefox esr, seamonkey, thunderbird, firefox os
Vulnerable Versions:
1.0.1, 1.0.2, 0, 12.04, 14.04, 14.10, 15.04, b.11.31, 8.5, r28.3.6, 7.0, 8.0, 1.6.0, 1.7.0, 1.8.0, 12, 11.0, 3.19, 38.1.0, 39.0, 31.8, 2.35, 38.1, 2.2

Timeline

Official Publish: May 21st, 2015
Last Modified: May 27th, 2026
Added to House: July 19th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.