← Vulnerability feed

Vulnerability record · CVE-2009-3555 · published 9 November 2009

CVE-2009-3555: TLS/SSL renegotiation flaw allows plaintext injection into sessions

Apache · Http Server

The TLS protocol and SSL 3.0 do not properly bind renegotiation handshakes to the existing connection, so a man-in-the-middle can inject data that the server processes as if it came from the authenticated client. This affects widely deployed implementations including IIS 7.0, Apache mod_ssl, OpenSSL, GnuTLS, NSS, and multiple Cisco products, making it a broad protocol-level issue rather than a single-vendor bug.

9.8 CVSS 3.1 Critical EPSS 87% · top 0.3% CWE-295 · Improper certificate validationCWE-300 · CWE-300
9.8CVSS 3.1 base score, v2 5.8
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
8Affected product versions listed by NVD
597References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw is a protocol-level integrity break with a critical CVSS score and very high EPSS, but it requires a man-in-the-middle position and is not listed in KEV, so it is high rather than critical for most defenders.

What it is

The TLS protocol and SSL 3.0 do not properly bind renegotiation handshakes to the existing connection, so a man-in-the-middle can inject data that the server processes as if it came from the authenticated client. This affects widely deployed implementations including IIS 7.0, Apache mod_ssl, OpenSSL, GnuTLS, NSS, and multiple Cisco products, making it a broad protocol-level issue rather than a single-vendor bug.

Impact

An attacker positioned on the network path can inject arbitrary plaintext into an HTTPS or TLS/SSL-protected session, potentially performing actions as the victim or poisoning application data. The flaw undermines the integrity of the protected channel, though confidentiality of the underlying session is not directly broken by the injection itself.

Attack surface

Reachable over the network by a man-in-the-middle who can intercept and modify traffic between client and server; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The attacker must already be positioned to intercept the connection.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.87264, 99.7th percentile) and at least one reference is tagged as an exploit, indicating mature public exploitation techniques exist.

What to do

  • Patch affected TLS/SSL implementations to versions that support RFC 5746 secure renegotiation (e.g., OpenSSL 0.9.8l or later, updated Apache mod_ssl, GnuTLS, NSS, and vendor builds).
  • Enable and enforce RFC 5746 secure renegotiation on servers and clients where supported.
  • Disable or restrict TLS/SSL renegotiation on servers that do not require it.
  • Where feasible, require client certificates or application-layer authentication so injected requests cannot be processed as the victim.
  • Retire end-of-life TLS/SSL stacks that cannot be updated to support secure renegotiation.

Detection

  • Monitor for unexpected TLS renegotiation events in server and load balancer logs, especially renegotiations that immediately precede state-changing requests.
  • Inspect network traffic for TLS handshake patterns inconsistent with the established session, such as renegotiation without proper binding.
  • Correlate application logs for requests that appear to originate from an authenticated session but lack matching client-side activity.
  • Track TLS library versions in use and alert on hosts still running implementations without RFC 5746 support.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/bugtraq/2013-11/0120.html Broken Link
http://blog.g-sec.lu/2009/11/tls-sslv3-renegotiation-vulnerability.html Third Party Advisory
http://blogs.iss.net/archive/sslmitmiscsrf.html Broken Link
http://blogs.sun.com/security/entry/vulnerability_in_tls_protocol_during Third Party Advisory
http://clicky.me/tlsvuln ExploitThird Party Advisory
http://extendedsubset.com/?p=8 Broken Link
http://extendedsubset.com/Renegotiating_TLS.pdf Broken Link
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686 Broken Link
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02436041 Broken Link
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751 Broken Link
http://kbase.redhat.com/faq/docs/DOC-20491 Third Party Advisory
http://lists.apple.com/archives/security-announce/2010//May/msg00001.html Mailing ListThird Party Advisory
http://lists.apple.com/archives/security-announce/2010//May/msg00002.html Mailing ListThird Party Advisory
http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html Mailing ListThird Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049455.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049528.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049702.html Third Party Advisory
http://lists.gnu.org/archive/html/gnutls-devel/2009-11/msg00029.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00009.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00005.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html Third Party Advisory
http://marc.info/?l=apache-httpd-announce&m=125755783724966&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=126150535619567&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=127128920008563&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=127419602507642&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=127557596201693&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=130497311408250&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=132077688910227&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=133469267822771&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=134254866602253&w=2 Third Party Advisory

Track CVE-2009-3555 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2009-3555), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.