OpenSSL SSLv2 Man-in-the-Middle Vulnerability under Top threats in Daily reports

cancel
Showing results for 
Search instead for 
Did you mean: 

OpenSSL SSLv2 Man-in-the-Middle Vulnerability under Top threats in Daily reports

L1 Bithead

I consistently get OpenSSL SSLv2 Man-in-the-Middle Vulnerability under Top Threats in Daily Reports.

What does this mean? am I getting attacked? is it reporting a vulnerability in devices? 

At what level should I be concerned with this?

1 REPLY 1

L7 Applicator

this is a warning that the SSL traffic passing through might be exploited

 

 

from threatvault.paloaltonetworks.com:

OpenSSL is prone to a man-in-the-middle vulnerability while parsing certain crafted SSL requests. The vulnerability is due to the lack of proper checks on SSL requests, leading to an exploitable man-in-the-middle vulnerability. An attacker could exploit the vulnerability by sending crafted SSL requests. A successful attack could lead to remote code execution with the privileges of the server.

 

 

if you go into your threat logs, you should be able to pinpoint where these connections are coming from/going to and take appropriate action (patch server, block connection, add exception)

 

Tom Piens
Like my answer? check out my book! https://bit.ly/MasteringPAN
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!