F5 Networks BIG-IP : OpenSSL vulnerability (SOL33209124) (deprecated)

high Nessus Plugin ID 88850

Synopsis

This plugin has been deprecated.

Description

ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.

This plugin has been deprecated. The advisory was updated to remove all affected versions the plugin covered.

Solution

n/a

See Also

http://www.nessus.org/u?b0b8821d

Plugin Details

Severity: High

ID: 88850

File Name: f5_bigip_SOL33209124.nasl

Version: Revision: 2.9

Type: local

Published: 2/19/2016

Updated: 4/26/2016

Configuration: Enable paranoid mode

Vulnerability Information

CPE: cpe:/a:f5:big-ip:access_policy_manager, cpe:/a:f5:big-ip:application_security_manager, cpe:/a:f5:big-ip:global_traffic_manager, cpe:/a:f5:big-ip:link_controller, cpe:/a:f5:big-ip:local_traffic_manager, cpe:/a:f5:big-ip:protocol_security_manager, cpe:/a:f5:big-ip:wan_optimization_manager, cpe:/a:f5:big-ip:web_accelerator_manager, cpe:/h:f5:big-ip

Required KB Items: Host/local_checks_enabled, Host/BIG-IP/hotfix, Host/BIG-IP/modules, Host/BIG-IP/version, Settings/ParanoidReport

Patch Publication Date: 1/28/2016

Reference Information

CVE: CVE-2015-3197