SSL Certificate Chain Contains Illegitimate TURKTRUST Intermediate CA

Medium Nessus Plugin ID 63398

Synopsis

The SSL certificate chain for this service is not to be trusted.

Description

The X.509 certificate chain sent by the remote host either contains or is signed by an intermediate Certificate Authority (CA) that was accidentally issued by TURKTRUST.

Certificate chains descending from this intermediate CA could allow an attacker to perform man-in-the-middle attacks and decode traffic.

Solution

Ensure that your software or operating system blacklists the intermediate CAs.

See Also

http://technet.microsoft.com/en-us/security/advisory/2798897

http://www.nessus.org/u?4d896fab

http://www.nessus.org/u?d92931ec

http://www.turktrust.com.tr/kamuoyu-aciklamasi.2.html

Plugin Details

Severity: Medium

ID: 63398

File Name: ssl_turktrust.nasl

Version: $Revision: 1.2 $

Type: remote

Family: General

Published: 2013/01/07

Modified: 2016/12/14

Dependencies: 56984

Risk Information

Risk Factor: Medium

CVSSv2

Base Score: 4

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Information

Required KB Items: Settings/ParanoidReport, SSL/Supported

Vulnerability Publication Date: 2012/12/26