SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Device (Encryption/VPN)  >   HPE VPN Firewall Module Vendors:   HPE
(HP Issues Fix for HP VPN Firewall Module) OpenSSL 'no-ssl3' Build Option Fails to Prevent SSL 3.0 Handshakes
SecurityTracker Alert ID:  1032510
SecurityTracker URL:  http://securitytracker.com/id/1032510
CVE Reference:   CVE-2014-3568   (Links to External Site)
Date:  Jun 5 2015
Impact:   Host/resource access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  

Description:   A vulnerability was reported in OpenSSL. A remote user can bypass the intended build configuration and use SSL 3.0. HP VPN Firewall Module is affected.

The system does not properly enforce the 'no-ssl3' build option. A server built with this option may accept SSL 3.0 sessions. A client built with this option may generate SSL 3.0 sessions.

The vendor was notified on October 14, 2014.

Akamai Technologies reported this vulnerability.

Impact:   A remote user can bypass the intended build configuration and use SSL 3.0.
Solution:   HP has issued an advisory for HP VPN Firewall Module.

For SecBlade FW (fixed version R3181P05):

JC635A HP 12500 VPN Firewall Module
JD245A HP 9500 VPN Firewall Module
JD249A HP 10500/7500 Advanced VPN Firewall Mod
JD250A HP 6600 Firewall Processing Rtr Module
JD251A HP 8800 Firewall Processing Module
JD255A HP 5820 VPN Firewall Module
H3C S9500E SecBlade VPN Firewall Module (0231A0AV)
H3C S7500E SecBlade VPN Firewall Module (0231A832)
H3C SR66 Gigabit Firewall Module (0231A88A)
H3C SR88 Firewall Processing Module (0231A88L)
H3C S5820 SecBlade VPN Firewall Module (0231A94J)

For F1000-E (fixed version R3181P05):

JD272A HP F1000-E VPN Firewall Appliance

For F1000-A (fixed version R3734P06):

JG214A HP F1000-A-EI VPN Firewall Appliance

For F1000-S (fixed version R3734P06):

JG213A HP F1000-S-EI VPN Firewall Appliance

The HP advisory is available at:

http://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04616259

Vendor URL:  h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04616259 (Links to External Site)
Cause:   Configuration error

Message History:   This archive entry is a follow-up to the message listed below.
Oct 15 2014 OpenSSL 'no-ssl3' Build Option Fails to Prevent SSL 3.0 Handshakes



 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2020, SecurityGlobal.net LLC