Transport Layer Security Renegotiation Vulnerability
1 Dec. 2009
Summary
Cisco has reported an industry-wide vulnerability that exists in the Transport Layer Security (TLS) protocol that could impact any product that uses any version of TLS and SSL. The vulnerability exists in how the protocol handles session renegotiation and exposes users to a potential man-in-the-middle attack.
Vulnerable Systems:
* All systems that use Transport Layer Security (TLS) protocol
TLS and its predecessor, SSL, are cryptographic protocols that provide security for communications over IP data networks such as the Internet. An industry-wide vulnerability exists in the TLS protocol that could impact any Cisco product that uses any version of TLS and SSL. The vulnerability exists in how the protocol handles session renegotiation and exposes users to a potential man-in-the-middle attack.
Cisco is currently evaluating its products for possible exposure to these TLS issues. Contact the manufacturer of any products that use TLS and SSL for more information and refer to this CVE number.
-------------------------------------------------------------------------------------------------------------------------------
This vulnerability and over 10,000 others are identified and reported by AVDS, the most technically sophisticated network vulnerability assessment and management system available.
*