Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-6653

Опубликовано: 01 мар. 2018
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

comforte SWAP 1049 through 1069 and 20.0.0 through 21.5.3 (as used in SSLOBJ on HPE NonStop SSL T0910, and in the comforte SecurCS, SecurFTP, SecurLib/SSL-AT, and SecurTN products), after executing the RELOAD CERTIFICATES command, does not ensure that clients use a strong TLS cipher suite, which makes it easier for remote attackers to defeat intended cryptographic protection mechanisms by sniffing the network. This is fixed in 21.6.0.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:comforte:swap:*:*:*:*:*:*:*:*
Версия от 20.0.0 (включая) до 21.5.3 (включая)
cpe:2.3:a:comforte:swap:*:*:*:*:*:*:*:*
Версия от 1049 (включая) до 1069 (включая)
cpe:2.3:h:hp:nonstop_server:-:*:*:*:*:*:*:*

EPSS

Процентиль: 18%
0.00058
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 5.3
github
больше 3 лет назад

comforte SWAP 1049 through 1069 and 20.0.0 through 21.5.3 (as used in SSLOBJ on HPE NonStop SSL T0910, and in the comforte SecurCS, SecurFTP, SecurLib/SSL-AT, and SecurTN products), after executing the RELOAD CERTIFICATES command, does not ensure that clients use a strong TLS cipher suite, which makes it easier for remote attackers to defeat intended cryptographic protection mechanisms by sniffing the network. This is fixed in 21.6.0.

EPSS

Процентиль: 18%
0.00058
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-326