Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20160330-01-OPENSSL
HistoryMar 30, 2016 - 12:00 a.m.

Security Advisory - OpenSSL DROWN Security Vulnerability

2016-03-3000:00:00
Huawei Technologies
www.huawei.com
43

0.952 High

EPSS

Percentile

99.4%

OpenSSL official website released a security advisory about a high risk vulnerability dubbed DROWN (CVE-2016-0800) on March 1st, 2016.

The vulnerability is: Once SSLv2 is used, an attacker can capture packets or act as a man in the middle (MIMT) to obtain SSL session keys, decrypt encrypted traffic, and obtain users’ sensitive information. (Vulnerability ID: HWPSIRT-2016-03007)

This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2016-0800.

Part of Huawei products have released software updates to fix this vulnerability. This advisory is available at the following link:

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160330-01-openssl-en