Lucene search

K
ibmIBM7384752C800D0ED425C7AC6639FE59E27356FD4BCA8151EB96EBEBC7B73589D1
HistoryJun 16, 2018 - 10:02 p.m.

Security Bulletin: IBM QRadar Network Security is affected by a less-secure algorithm during negotiations vulnerability (CVE-2017-1491)

2018-06-1622:02:06
www.ibm.com
13

EPSS

0.001

Percentile

34.7%

Summary

IBM QRadar Network Security has addressed less-secure algorithm during negotiations

Vulnerability Details

CVEID: CVE-2017-1491**
DESCRIPTION:** IBM QRadar Network Security supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties.
CVSS Base Score: 5.9
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/128689&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

IBM QRadar Network Security 5.4

Remediation/Fixes

Product

| VRMF| Remediation/First Fix
—|—|—
IBM QRadar Network Security| Firmware version 5.4| Install Firmware 5.4.0.2 from the Available Updates page of the Local Management Interface, or by performing a One Time Scheduled Installation from SiteProtector.
Or
Download Firmware 5.4.0.2 from IBM Security License Key and Download Center and upload and install via the Available Updates page of the Local Management Interface.

Workarounds and Mitigations

None

EPSS

0.001

Percentile

34.7%

Related for 7384752C800D0ED425C7AC6639FE59E27356FD4BCA8151EB96EBEBC7B73589D1