Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.145406
Categoría:Denial of Service
Título:OpenSSL: Incorrect SSLv2 rollback protection (CVE-2021-23839) - Windows
Resumen:OpenSSL is prone to an incorrect SSLv2 rollback protection vulnerability.
Descripción:Summary:
OpenSSL is prone to an incorrect SSLv2 rollback protection vulnerability.

Vulnerability Insight:
OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with
a server that is configured to support both SSLv2 and more recent SSL and TLS versions then a check is made
for a version rollback attack when unpadding an RSA signature. Clients that support SSL or TLS versions
greater than SSLv2 are supposed to use a special form of padding. A server that supports greater than SSLv2
is supposed to reject connection attempts from a client where this special form of padding is present,
because this indicates that a version rollback has occurred (i.e. both client and server support greater
than SSLv2, and yet this is the version that is being requested).

The implementation of this padding check inverted the logic so that the connection attempt is accepted if
the padding is present, and rejected if it is absent. This means that such as server will accept a connection
if a version rollback attack has occurred. Further the server will erroneously reject a connection if a
normal SSLv2 connection attempt is made.

Affected Software/OS:
OpenSSL versions 1.0.2s - 1.0.2x.

Solution:
Update to version 1.0.2y, 1.1.1j or later. See the references for
more details.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2021-23839
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=30919ab80a478f2d81f2e9acdcca3fa4740cd547
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44846
https://security.netapp.com/advisory/ntap-20210219-0009/
https://www.openssl.org/news/secadv/20210216.txt
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com/security-alerts/cpuApr2021.html
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpuoct2021.html
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.