When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.
Conclusion & alert: CVE-2018-12384 is rated Moderate Risk (49.2/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.49%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.62% | 1.49% | +0.87% |
| 2 | 2026-05-14 | 0.68% | 0.62% | -0.06% |
| 3 | 2026-05-01 | — | 0.68% | — |
Full EPSS history (22 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.9 | 3.0 | MEDIUM |
|
2.2 | 3.6 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
medium | CVE-2018-12384: 1 source package rows (nss); 11 state rows across 11 repos (3.10-main, 3.11-main, 3.12-main, 3.17-community, 3.18-community, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-community, edge-main); fixed 11, open 0. | https://security.alpinelinux.org/vuln/CVE-2018-12384 |
debian
|
low | CVE-2018-12384 low priority: Debian including 1 source packages (nss), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2018-12384 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2018-12384 |
suse
|
medium | CVE-2018-12384 severity moderate: SUSE including 513 source package names (1.0.0.1862.1.5.2:libfreebl3-3.40.1-3.7.2, 1.0.0.1862.1.5.2:libsoftokn3-3.40.1-3.7.2, …), 1425 product×package rows across 338 product lines (Container bci/bci-sle15-kernel-module-devel, Container bci/kiwi, … (338 product lines)): Fixed 1113, Known Affected 157, Known Not Affected 155. | https://www.suse.com/security/cve/CVE-2018-12384/ |
ubuntu
|
low | CVE-2018-12384 low priority: Ubuntu including 1 source packages (nss), 5 status rows across 5 suites (bionic, cosmic, trusty, upstream, xenial): released 5. | https://ubuntu.com/security/CVE-2018-12384 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| mozilla | network_security_services | < 3.39 | cpe:2.3:a:mozilla:network_security_services:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=CVE-2018-12384 | Issue Tracking Vendor Advisory |
| https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html |