whaust
2019年12月20日 星期五
Padding-oracle attack on TLS CBC cipher mode (CVE-2014-8730) (PAN-SA-2015-0001)
Padding-oracle attack on TLS CBC cipher mode (CVE-2014-8730) (PAN-SA-2015-0001)
Last revised: 01/12/2015
Summary
A vulnerability affecting some implementations of TLS 1.x with CBC cipher modes has been discovered that allows an attacker to decrypt some encrypted contents under certain conditions (CVE-2014-8730). This padding-oracle attack on TLS CBC cipher modes is a variant of the POODLE vulnerability, commonly known as “POODLE Bites”. This issue is confirmed to affect PAN-OS implementation of TLS 1.x. (Ref #72544)
Severity: Low
The conditions of successful exploitation are similar to the POODLE and BEAST attacks, which require several conditions to be met for successful exploitation (i.e. the attacker requires a man-in-the-middle position in the network and must also be able to direct the victim client to send many repeated requests to the vulnerable server on behalf of the attacker via scripting, web sockets, or similar mechanism). Due to the conditions required of a successful attack scenario, the risk of exploitation is not particularly high. More information can be found in Microsoft Security Advisory 3009008 (https://technet.microsoft.com/library/security/3009008).
Products Affected
PAN-OS 6.1.1 and earlier; PAN-OS 6.0.8 and earlier; PAN-OS 5.0.15 and earlier
Available Updates
A patch for the issue described in this bulletin will be made available in a regularly scheduled maintenance update for each supported release of PAN-OS. This bulletin will be updated as the releases are made available.
Workarounds and Mitigations
Customers can enable signature 37144 (“POODLE Bites Vulnerability”) to block attempted TLS sessions using CBC mode on firewall policy securing traffic to sensitive services (e.g. device management). Support for deprecated cipher suites should be disabled on all clients where possible. Device management services should also be restricted to a dedicated vlan or otherwise segmented trusted network to prevent exposure to untrusted hosts where possible.
Acknowledgements
N/A
訂閱:
張貼留言 (Atom)
Popular
-
При планировании проекта разработки программного обеспечения я часто сталкиваюсь с помощником, который задает мне вопрос: в чем разница межд...
-
소프트웨어 개발 프로젝트를 계획 할 때 종종 어시스턴트가 질문을하는데 SA, SD, SE의 차이점은 무엇입니까? 이전에이 질문을 해본 적이 있는데 상당히 당혹 스럽습니다. 시스템 분석과 시스템 설계와 시스템 엔지니어링의 차이점은 무엇입니까? SA와...
-
VOC(Voice of Customer)即「顧客之聲」 ,指的是從顧客處收集來的意見、回饋、需求或期望。這些資訊通常來自於調查、反饋表單、客服查詢、產品評論或社交媒體互動等多種管道。企業透過VOC數據來了解顧客對產品或服務的看法,以便改進產品設計、提升服務質量,並最終提高顧客...
沒有留言:
張貼留言