Synced 30 Sept 2026 20:54 UTC Account
← All products

CVE-2020-1596

MEDIUM severity · CVSS 5.4 · CWE-327
5.4CVSS MEDIUM

Summary

<p>A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfully exploited this vulnerability could obtain information to further compromise a users's encrypted transmission channel.</p> <p>To exploit the vulnerability, an attacker would have to conduct a man-in-the-middle attack.</p> <p>The update addresses the vulnerability by correcting how TLS components use hash algorithms.</p>

Impact & exploitability

Attack vectorAdjacent
Attack complexityHigh
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactLow
Availability impactNone
Exploit probability (EPSS)1%

CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1596 ↗