F5 Networks BIG-IP : OpenSSL vulnerability (SOL33209124) (deprecated)

high Nessus Plugin ID 88850

Synopsis

This plugin has been deprecated.

Description

ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.

This plugin has been deprecated. The advisory was updated to remove all affected versions the plugin covered.

Solution

n/a

See Also

http://www.nessus.org/u?b0b8821d

Plugin Details

Severity: High

ID: 88850

File Name: f5_bigip_SOL33209124.nasl

Version: Revision: 2.9

Type: local

Published: 2/19/2016

Updated: 4/26/2016

Dependencies: f5_bigip_detect.nbin

Configuration: Enable paranoid mode

Risk Information

Risk Factor: High

Vulnerability Information

CPE: cpe:2.3:h:f5:big-ip:*:*:*:*:*:*:*:*, cpe:2.3:a:f5:big-ip:access_policy_manager:*:*:*:*:*:*:*, cpe:2.3:a:f5:big-ip:application_security_manager:*:*:*:*:*:*:*, cpe:2.3:a:f5:big-ip:global_traffic_manager:*:*:*:*:*:*:*, cpe:2.3:a:f5:big-ip:link_controller:*:*:*:*:*:*:*, cpe:2.3:a:f5:big-ip:local_traffic_manager:*:*:*:*:*:*:*, cpe:2.3:a:f5:big-ip:protocol_security_manager:*:*:*:*:*:*:*, cpe:2.3:a:f5:big-ip:wan_optimization_manager:*:*:*:*:*:*:*, cpe:2.3:a:f5:big-ip:web_accelerator_manager:*:*:*:*:*:*:*

Required KB Items: Host/local_checks_enabled, Settings/ParanoidReport, Host/BIG-IP/hotfix, Host/BIG-IP/modules, Host/BIG-IP/version

Patch Publication Date: 1/28/2016

Reference Information

CVE: CVE-2015-3197