|
JP1/HiCommand Series Products OpenSSL Insecure Protocol Negotiation Weakness
JP1/HiCommand Series Products are prone to a remote protocol-negotiation weakness due to a design error. Successful exploits may allow an attacker connecting to the affected server to replace the SSL 3 or TLS 1 protocol with the SSL 2 protocol. This may allow the attacker to exploit insecurities in SSL version 2 to gain access to or tamper with the clear-text communications between the targeted client and server. NOTE: This issue may be related to BID 15071 (OpenSSL Insecure Protocol Negotiation Weakness). |
|
|
Privacy Statement |