OpenSSL 1.0.1 < 1.0.1r / 1.0.2 < 1.0.2f Information Disclosure
Medium Nessus Network Monitor Plugin ID 9464
SynopsisThe remote web server is running an outdated instance of OpenSSL and that is affected by an Information Disclosure vulnerability.
DescriptionAccording to its banner, the version of OpenSSL on the remote host is 1.0.2 prior to 1.0.2f or 1.0.1 prior to 1.0.1r and is affected by a flaw that is triggered when handling cipher negotiation. This may allow a remote attacker to negotiate SSLv2 ciphers that are disabled on the server.
SolutionUpgrade OpenSSL to version 1.0.2f or higher. If 1.0.2 cannot be obtained, 1.0.1r has also been patched for this vulnerability.