OpenSSL < 0.9.8q / 1.0.0c Multiple Vulnerabilities

This script is Copyright (C) 2010-2015 Tenable Network Security, Inc.

Synopsis :

The remote web server is affected by multiple vulnerabilities.

Description :

According to its banner, the remote web server is running a version
of OpenSSL older than 0.9.8q or 1.0.0c. Such versions are potentially
affected by multiple vulnerabilities :

- It may be possible to downgrade the ciphersuite to a
weaker version by modifying the stored session cache

- An error exists in the J-PAKE implementation that could
lead to successful validation by someone with no
knowledge of the shared secret.

See also :

Solution :

Upgrade to OpenSSL 0.9.8q / 1.0.0c or later.

Risk factor :

High / CVSS Base Score : 7.5
CVSS Temporal Score : 6.5
Public Exploit Available : false

Family: Web Servers

Nessus Plugin ID: 51058 ()

Bugtraq ID: 45163

CVE ID: CVE-2010-4180