Cisco ACE30 and ACE4710 OpenSSL 'ChangeCipherSpec' MiTM Vulnerability

This script is Copyright (C) 2014-2016 Tenable Network Security, Inc.


Synopsis :

The remote host is affected by a man-in-the-middle vulnerability.

Description :

The remote device is running a software version known to be affected
by an OpenSSL related vulnerability. The flaw could allow a MiTM
attacker to decrypt or forge SSL messages by telling the service to
begin encrypted communications before key material has been exchanged,
which causes predictable keys to be used to secure future traffic.

See also :

http://www.nessus.org/u?5539aa9d
https://www.openssl.org/news/secadv/20140605.txt

Solution :

There is currently no known solution.

Risk factor :

Medium / CVSS Base Score : 6.8
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 5.3
(CVSS2#E:POC/RL:OF/RC:C)
Public Exploit Available : true

Family: CISCO

Nessus Plugin ID: 76127 ()

Bugtraq ID: 67899

CVE ID: CVE-2014-0224

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial