|
Brought to you by:
Suppliers of:
|
|
|
| |
| Cisco has reported an industry-wide vulnerability that exists in the Transport Layer Security (TLS) protocol that could impact any product that uses any version of TLS and SSL. The vulnerability exists in how the protocol handles session renegotiation and exposes users to a potential man-in-the-middle attack. |
| |
Credit:
The information has been provided by Marsh Ray, Steve Dispensa and Cisco PSIRT.
The original article can be found at: http://www.cisco.com/warp/public/707/cisco-sa-20091109-tls.shtml
|
| |
Vulnerable Systems:
* All systems that use Transport Layer Security (TLS) protocol
TLS and its predecessor, SSL, are cryptographic protocols that provide security for communications over IP data networks such as the Internet. An industry-wide vulnerability exists in the TLS protocol that could impact any Cisco product that uses any version of TLS and SSL. The vulnerability exists in how the protocol handles session renegotiation and exposes users to a potential man-in-the-middle attack.
Cisco is currently evaluating its products for possible exposure to these TLS issues. Contact the manufacturer of any products that use TLS and SSL for more information and refer to this CVE number.
CVE Information:
CVE-2009-3555
-------------------------------------------------------------------------------------------------------------------------------
This vulnerability and over 10,000 others are identified and reported by AVDS, the most technically sophisticated network vulnerability assessment and management system available.
*
|
|
|
|
|