This script is Copyright (C) 2012-2014 Tenable Network Security, Inc.
The remote server is vulnerable to man-in-the-middle attacks.
According to its banner, the remote server is running a version of
OpenSSL that is earlier than 0.9.7h or 0.9.8a.
If the SSL_OP_MSIE_SSLV2_RSA_PADDING option is used, a remote attacker
could force a client to downgrade to a weaker protocol and implement a
See also :
Upgrade to OpenSSL 0.9.7h / 0.9.8a or later.
Risk factor :
Medium / CVSS Base Score : 5.0
CVSS Temporal Score : 3.7
Public Exploit Available : false
Family: Web Servers
Nessus Plugin ID: 17755 ()
Bugtraq ID: 15647
CVE ID: CVE-2005-2969
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.