HP Version Control Agent (VCA) Heartbeat Information Disclosure (Heartbleed)
High Nessus Plugin ID 77024
SynopsisThe remote host contains software that is affected by an information disclosure vulnerability.
DescriptionThe installation of HP Version Control Agent (VCA) on the remote Windows host is version 7.2.0, 7.2.1, 7.2.2, 7.3.0, or 7.3.1. It is, therefore, affected by an information disclosure vulnerability.
An out-of-bounds read error, known as the 'Heartbleed Bug', exists related to handling TLS heartbeat extensions that could allow an attacker to obtain sensitive information such as primary key material, secondary key material, and other protected content.
SolutionUpgrade to VCA 7.3.2 or later.