- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-26-2021 06:04 AM
I consistently get OpenSSL SSLv2 Man-in-the-Middle Vulnerability under Top Threats in Daily Reports.
What does this mean? am I getting attacked? is it reporting a vulnerability in devices?
At what level should I be concerned with this?
05-26-2021 06:20 AM
this is a warning that the SSL traffic passing through might be exploited
from threatvault.paloaltonetworks.com:
OpenSSL is prone to a man-in-the-middle vulnerability while parsing certain crafted SSL requests. The vulnerability is due to the lack of proper checks on SSL requests, leading to an exploitable man-in-the-middle vulnerability. An attacker could exploit the vulnerability by sending crafted SSL requests. A successful attack could lead to remote code execution with the privileges of the server.
if you go into your threat logs, you should be able to pinpoint where these connections are coming from/going to and take appropriate action (patch server, block connection, add exception)
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!