Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

JP1/HiCommand Series Products OpenSSL Insecure Protocol Negotiation Weakness

JP1/HiCommand Series Products are prone to a remote protocol-negotiation weakness due to a design error.

Successful exploits may allow an attacker connecting to the affected server to replace the SSL 3 or TLS 1 protocol with the SSL 2 protocol. This may allow the attacker to exploit insecurities in SSL version 2 to gain access to or tamper with the clear-text communications between the targeted client and server.

NOTE: This issue may be related to BID 15071 (OpenSSL Insecure Protocol Negotiation Weakness).







 

Privacy Statement
Copyright 2009, SecurityFocus