← Vulnerability feed

Vulnerability record · CVE-2020-12872 · published 15 May 2020

CVE-2020-12872: Yaws inadequate encryption strength vulnerability

Yaws · Yaws

yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if running on an Erlang/OTP virtual machine with a version less than 21.0.

5.5 CVSS 3.1 Medium EPSS 0.39% · top 69.6% CWE-326 · Inadequate encryption strength
5.5CVSS 3.1 base score, v2 2.1
0.39%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if running on an Erlang/OTP virtual machine with a version less than 21.0.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-12872 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-24379Yaws xml external entity (xxe) vulnerabilityWebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.EPSS 3.4%9.8CVE-2020-24916Yaws os command injection vulnerabilityCGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.EPSS 17%7.5CVE-2017-10974Yaws web server path traversal allows unauthenticated file disclosureYaws 1.91 fails to properly block HTTP directory traversal when a request path begins with the /%5C sequence, letting an attacker read files outside …EPSS 81%analysed6.5CVE-2011-4350Yaws path traversal vulnerabilityYaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain co…EPSS 16%6.1CVE-2016-1000108Yaws open redirect vulnerabilityyaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the pr…EPSS 1.1%5.0CVE-2010-4181Yaws path traversal vulnerabilityDirectory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequences.EPSS 8.5%5.0CVE-2009-4495Yaws improper input validation vulnerabilityYaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or po…EPSS 9.0%5.0CVE-2009-0751Yaws vulnerabilityYaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers.EPSS 10%

Source: NIST National Vulnerability Database (record CVE-2020-12872), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.