SSL/TLS Certificate Signed Using Weak Hashing Algorithm

medium Web App Scanning Plugin ID 112542

Synopsis

SSL/TLS Certificate Signed Using Weak Hashing Algorithm

Description

The remote server uses an SSL/TLS certificate that has been signed using a cryptographically weak hashing algorithm (e.g. MD2, MD4, MD5, or SHA1). These signature algorithms are known to be vulnerable to collision attacks. An attacker can exploit this to generate another certificate with the same digital signature, allowing an attacker to masquerade as the affected service.

Solution

Purchase or generate a new SSL/TLS certificate using SHA-2 signature algorithm to replace the existing one.

Plugin Details

Severity: Medium

ID: 112542

Type: remote

Family: SSL/TLS

Published: 2/4/2019

Updated: 11/26/2021

Scan Template: api, basic, config_audit, full, mcp, pci, quick, scan, ssl_tls

Risk Information

VPR

Risk Factor: Low

Score: 2.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CVSS Score Source: Tenable

CVSS v4

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: Tenable

Reference Information