Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

OpenSSL 1.0.1 < 1.0.1r / 1.0.2 < 1.0.2f Information Disclosure



The remote web server is running an outdated instance of OpenSSL and that is affected by an Information Disclosure vulnerability.


According to its banner, the version of OpenSSL on the remote host is 1.0.2 prior to 1.0.2f or 1.0.1 prior to 1.0.1r and is affected by a flaw that is triggered when handling cipher negotiation. This may allow a remote attacker to negotiate SSLv2 ciphers that are disabled on the server.


Upgrade OpenSSL to version 1.0.2f or higher. If 1.0.2 cannot be obtained, 1.0.1r has also been patched for this vulnerability.