Apache mod_ssl SSLCipherSuite Directive Vulnerability

Apache mod_ssl SSLCipherSuite Directive Vulnerability

CVE-2004-0885 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.

Learn more about our Cis Benchmark Audit For Apache Http Server.