PT-2010-3892 · Sourcefire · Sourcefire 3D Sensor+1

Publicado

2010-06-16

·

Atualizado

2018-10-10

·

CVE-2010-2306

CVSS v2.0

4.3

Média

VetorAV:A/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Sourcefire 3D Sensor versions 1000, 2000, and 9900 Sourcefire Defense Center version 1000
Description The issue allows remote attackers to decrypt SSL traffic via a man-in-the-middle (MITM) attack due to the use of the same static, private SSL keys for multiple devices and installations.
Recommendations For Sourcefire 3D Sensor versions 1000, 2000, and 9900, regenerate unique SSL keys for each device. For Sourcefire Defense Center version 1000, regenerate unique SSL keys for each installation. As a temporary workaround, consider restricting access to sensitive data transmitted over SSL until unique keys are generated.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2306

Produtos afetados

Sourcefire 3D Sensor
Sourcefire Defense Center