This module exploits a vulnerability in OpenSSL by sending a "Change Ciper Spec" message to the server.
This vulnerability allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake.
This vulnerability allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake.
CVE Link
Exploit Type - Old
Exploits/Remote
Exploit Platform
Product Name