CVE-2011-3389
Is CVE-2011-3389 real, exploitable, or a false positive? Here's the community verdict.
signals
public sources
Lower base score, but a notable exploitation probability. Don't dismiss it on score alone.
public exploits
links to sources — we don’t host codeUnverified proof-of-concept code has been published. It may or may not be functional — assess before relying on it.
scanner noise
anonymous, aggregated from real reports · via Denoizr| Scanner | Flagged in | Turned out noise |
|---|---|---|
| Wiz | 1 scan | 0% |
How often this CVE was flagged by each scanner and how much turned out to be noise (false positives), aggregated anonymously from de-noised reports. Higher noise means the alert is more often not a real risk — verify your exposure.
baseline read
auto · not a community verdict
Low signal — verdict needed
Few public signals point to active risk. Whether a scanner hit here is a true or false positive depends on your version and config — community verdicts decide.
Based on CVSS · FIRST EPSS
Confirm or dispute →AV:N/AC:M/Au:N/C:P/I:N/A:N
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.
References
Published
Embed this verdict
[](https://www.truepositive.app/cve/CVE-2011-3389)<a href="https://www.truepositive.app/cve/CVE-2011-3389"><img src="https://www.truepositive.app/cve/CVE-2011-3389/badge.svg" alt="TruePositive verdict for CVE-2011-3389"></a>Live badge that updates automatically as the community verdict changes.
Community ground truth
Be the first practitioner to weigh in
So far this is only TruePositive's editorial baseline from public sources. Add your real-world verdict below — it becomes the signal the next person triaging this relies on.
🥇 The first 50 practitioners to contribute earn a Founding Contributor badge.
In your experience, is this finding real and exploitable?
awaiting field verdictsCurated baseline: A curated baseline from public sources, shown separately from community verdicts.
No account needed. Anonymous verdicts post as an unverified signal. Log in to make yours verified and earn reputation.
Field notes & remediation
Verdicts are the quick signal. Notes are the evidence and fixes behind them.
- 0
No confirmed in-the-wild exploitation or public exploit was found for this yet. FIRST EPSS estimates about a 73% chance of exploitation in the next 30 days, which is high relative to most CVEs.
Add a field note or remediationoptional
Related CVEs
Same weakness: CWE-326.
- CVE-2017-1000486CRIT 9.8KEVEPSS 94%
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
- CVE-2017-11317CRIT 9.8KEVEPSS 83%
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
- CVE-2018-18325HIGH 7.5KEVEPSS 74%
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
- CVE-2018-15811HIGH 7.5KEVEPSS 74%
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.