Sploitus

CVE-2020-12872

1 known exploit for CVE-2020-12872

yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if running on an Erlang/OTP virtual machine with a version less than 21.0.

Affected products
Erlang/Otp, Yaws
Yaws
≤ 2.0.6
Fix
Available
CVSS 3.1
5.5 MEDIUM
EPSS
0.4% (32th percentile)
Weakness
CWE-326
NVD status
Modified
Published
2020-05-15
CVE-2020-12872 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2020-12872

Proof-of-concept code and exploit modules indexed by Sploitus