Friday, January 29, 2016

Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products

On January 28, 2016, the OpenSSL Project released a security advisory detailing two vulnerabilities.

Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to conduct man-in-the-middle attacks on the SSL/TLS connection.

This advisory will be updated as additional information becomes available.

Cisco will release software updates that address these vulnerabilities.

Workarounds that mitigate these vulnerabilities are not available.

This advisory is available at the following link:
http://ift.tt/1PYw2TV

from Cisco Security Advisory http://ift.tt/1PYw2TV

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.