RSA Authentication Manager CVE-2016-0800 "DROWN" Vulnerability - False Positive
Originally Published: 2016-03-02
Article Number
Applies To
RSA Authentication Manager 7.1.4 / 3.0.4
CVE Identifier(s)
Article Summary
And related vulnerabilities:
CVE-2016-0705, CVE-2016-0798, CVE-2016-0797, CVE-2016-0799, CVE-2016-0703, CVE-2016-0704
Link to Advisories
Alert Impact
Not Applicable
Alert Impact Explanation
A cross-protocol attack was discovered that could lead to decryption of TLS
sessions by using a server supporting SSLv2 and EXPORT cipher suites as a
Bleichenbacher RSA padding oracle. Note that traffic between clients and
non-vulnerable servers can be decrypted provided another server supporting
SSLv2 and EXPORT ciphers (even with a different protocol such as SMTP, IMAP or
POP) shares the RSA keys of the non-vulnerable server. This vulnerability is
known as DROWN (CVE-2016-0800).
Recovering one session key requires the attacker to perform approximately 2^50
computation, as well as thousands of connections to the affected server. A more
efficient variant of the DROWN attack exists against unpatched OpenSSL servers
using versions that predate 1.0.2a, 1.0.1m, 1.0.0r and 0.9.8zf released on
19/Mar/2015 (see CVE-2016-0703).
Users can avoid this issue by disabling the SSLv2 protocol in all their SSL/TLS
servers, if they've not done so already. Disabling all SSLv2 ciphers is also
sufficient, provided the patches for CVE-2015-3197 (fixed in OpenSSL 1.0.1r and
1.0.2f) have been deployed. Servers that have not disabled the SSLv2 protocol,
and are not patched for CVE-2015-3197 are vulnerable to DROWN even if all SSLv2
ciphers are nominally disabled, because malicious clients can force the use of
SSLv2 with EXPORT ciphers.
Resolution
Notes
Upgraded OpenSSL to openssl-0.9.8j-0.89.1 in Third Party Patch v2 as per https://www.suse.com/security/cve/CVE-2016-0800.html
To confirm:
~> rpm -qa | grep openssl libopenssl0_9_8-0.9.8j-0.89.1 openssl-0.9.8j-0.89.1
Disclaimer
Related Articles
Infineon Trusted Platform Module (TPM) Vulnerability (CVE-2017-15361) Impact on RSA Products 59Number of Views CVE-2021-41617 Security vulnerability for RSA Authentication Manager 8.6.x 191Number of Views Security vulnerabilities CVE-2020-14882, CVE-2020-14883 and CVE-2020-14750, others in WebLogic an internal component in We… 432Number of Views RSA Customer Advisory: Spring Framework Spring4Shell Vulnerabilities CVE-2022-22965 CVE-2022-22950 CVE-2022-22963 181Number of Views Advisory regarding vulnerabilities reported by Oracle Java CVEs for applications running untrusted code 184Number of Views
Trending Articles
Unable to login to RSA Authentication Manager Security Console as super admin Authentication Manager Administration Server with operations console service Fails to Start with "No config.xml Was Found"… Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update RSA Authentication Manager Upgrade Process Authentication Manager How to Retrieve the LDAPS Certificate and Configure an External Identity Source to Use LDAPS
Don't see what you're looking for?