Search:     Advanced search
server monitoring

Deprecated SSL Protocol Usage

Article ID: 20007
Last updated: 27 Jan, 2009
Views: 1944
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

Deprecated SSL Protocol Usage

This script is Copyright (C) 2005-2007 Tenable Network Security

FamilyGeneral
Plugin ID20007
Bugtraq ID
CVE ID

Description:

Synopsis :

The remote service encrypts traffic using a protocol with known
weaknesses.

Description :

The remote service accepts connections encrypted using SSL 2.0, which
reportedly suffers from several cryptographic flaws and has been
deprecated for several years. An attacker may be able to exploit
these issues to conduct man-in-the-middle attacks or decrypt
communications between the affected service and clients.

See also :

http://www.schneier.com/paper-ssl.pdf

Solution :

Consult the applications documentation to disable SSL 2.0 and use SSL
3.0 or TLS 1.0 instead.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
This article was:   Helpful | Not Helpful
Prev   Next
Information about the scan     CVS pserver CVSROOT passwd file cmd exec