CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2011-3389: chrome Version not applicable in the source CPE; +15 more affected products

CVE-2011-3389. CVSS 2.0 base score 4.3 (MEDIUM, NVD). EPSS 0.73327 (percentile 0.99453), scored 2026-10-08.

Affected technology

chrome · Version not applicable in the source CPE
google

internet explorer · Version not applicable in the source CPE
microsoft

firefox · Version not applicable in the source CPE
mozilla

opera browser · Version not applicable in the source CPE
opera

windows · Version not applicable in the source CPE
microsoft

simatic rf68xr firmware · before 3.2.1 (exclusive)
siemens

simatic rf615r firmware · before 3.2.1 (exclusive)
siemens

curl · from 7.10.6 (inclusive), through 7.23.1 (inclusive)
haxx

enterprise linux desktop · 5.0
redhat

enterprise linux desktop · 6.0
redhat

enterprise linux eus · 6.2
redhat

enterprise linux server · 5.0
redhat

enterprise linux server · 6.0
redhat

enterprise linux server aus · 6.2
redhat

enterprise linux workstation · 5.0
redhat

enterprise linux workstation · 6.0
redhat

debian linux · 5.0
debian

debian linux · 6.0
debian

ubuntu linux · 10.04
canonical

ubuntu linux · 10.10
canonical

ubuntu linux · 11.04
canonical

ubuntu linux · 11.10
canonical

n/a · n/a
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (NVD, CVSS 2.0): Network (remote)

What an attacker can do

Man-in-the-middle attackers can obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack. NVD’s CVSS 2.0 assessment (base score 4.3/10) rates confidentiality impact as partial; integrity and availability impact as none.

Published

CWE
CWE-326
CCR priority
35.5 /100 (P4)
CVSS 2.0
4.3 /10 · CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:N/A:N · NVD
EPSS
0.73327 · percentile 0.99453 · 2026-10-09
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2011-3389.html