Cisco ACE30 and ACE4710 OpenSSL 'ChangeCipherSpec' MiTM Vulnerability

This script is Copyright (C) 2014 Tenable Network Security, Inc.


Synopsis :

The remote host is affected by a man-in-the-middle vulnerability.

Description :

The remote device is running a software version known to be affected
by an OpenSSL related vulnerability. The flaw could allow a MiTM
attacker to decrypt or forge SSL messages by telling the service to
begin encrypted communications before key material has been exchanged,
which causes predictable keys to be used to secure future traffic.

See also :

http://www.nessus.org/u?5539aa9d
http://www.openssl.org/news/secadv_20140605.txt

Solution :

There is currently no known solution.

Risk factor :

Medium / CVSS Base Score : 6.8
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 5.9
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : true

Family: CISCO

Nessus Plugin ID: 76127 ()

Bugtraq ID: 67899

CVE ID: CVE-2014-0224