Vulnerability record · CVE-2009-3555 · published 9 November 2009
CVE-2009-3555: TLS/SSL renegotiation flaw allows plaintext injection into sessions
Apache · Http Server
The TLS protocol and SSL 3.0 do not properly bind renegotiation handshakes to the existing connection, so a man-in-the-middle can inject data that the server processes as if it came from the authenticated client. This affects widely deployed implementations including IIS 7.0, Apache mod_ssl, OpenSSL, GnuTLS, NSS, and multiple Cisco products, making it a broad protocol-level issue rather than a single-vendor bug.
Description
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is a protocol-level integrity break with a critical CVSS score and very high EPSS, but it requires a man-in-the-middle position and is not listed in KEV, so it is high rather than critical for most defenders.
What it is
The TLS protocol and SSL 3.0 do not properly bind renegotiation handshakes to the existing connection, so a man-in-the-middle can inject data that the server processes as if it came from the authenticated client. This affects widely deployed implementations including IIS 7.0, Apache mod_ssl, OpenSSL, GnuTLS, NSS, and multiple Cisco products, making it a broad protocol-level issue rather than a single-vendor bug.
Impact
An attacker positioned on the network path can inject arbitrary plaintext into an HTTPS or TLS/SSL-protected session, potentially performing actions as the victim or poisoning application data. The flaw undermines the integrity of the protected channel, though confidentiality of the underlying session is not directly broken by the injection itself.
Attack surface
Reachable over the network by a man-in-the-middle who can intercept and modify traffic between client and server; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The attacker must already be positioned to intercept the connection.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.87264, 99.7th percentile) and at least one reference is tagged as an exploit, indicating mature public exploitation techniques exist.
What to do
- Patch affected TLS/SSL implementations to versions that support RFC 5746 secure renegotiation (e.g., OpenSSL 0.9.8l or later, updated Apache mod_ssl, GnuTLS, NSS, and vendor builds).
- Enable and enforce RFC 5746 secure renegotiation on servers and clients where supported.
- Disable or restrict TLS/SSL renegotiation on servers that do not require it.
- Where feasible, require client certificates or application-layer authentication so injected requests cannot be processed as the victim.
- Retire end-of-life TLS/SSL stacks that cannot be updated to support secure renegotiation.
Detection
- Monitor for unexpected TLS renegotiation events in server and load balancer logs, especially renegotiations that immediately precede state-changing requests.
- Inspect network traffic for TLS handshake patterns inconsistent with the established session, such as renegotiation without proper binding.
- Correlate application logs for requests that appear to originate from an authenticated session but lack matching client-side activity.
- Track TLS library versions in use and alert on hosts still running implementations without RFC 5746 support.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-3555 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-3555), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.