OpenSSL vulnerabilities were disclosed on January 8, 2015 by the
OpenSSL Project. This includes “FREAK: Factoring Attack on
RSA-EXPORT keys” TLS/SSL client and server vulnerability. OpenSSL
is used by System x Integrated Management Module (IMM). IMM has
addressed the applicable CVEs.
OpenSSL vulnerabilities were disclosed on January 8, 2015 by the OpenSSL Project. This includes “FREAK: Factoring Attack on RSA-EXPORT keys” TLS/SSL client and server vulnerability. OpenSSL is used by System x Integrated Management Module (IMM). IMM has addressed the applicable CVEs.
Vulnerability Details:
CVE-ID: CVE-2015-0204
Description: A vulnerability in the OpenSSL ssl3_get_key_exchange function could allow a remote attacker to downgrade the security of certain TLS connections. An OpenSSL client accepts the use of an RSA temporary key in a non-export RSA key exchange ciphersuite. This could allow a remote attacker using man-in-the-middle techniques to facilitate brute-force decryption of TLS/SSL traffic between vulnerable clients and servers. This vulnerability is also known as the FREAK attack.
CVSS Base Score: 4.3
CVSS Temporal Score: See <http://xforce.iss.net/xforce/xfdb/99707> for current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVE-ID: CVE-2014-3570
Description: An unspecified error in OpenSSL related to the production of incorrect results on some platforms by Bignum squaring (BN_sqr) has an unknown attack vector and impact.
CVSS Base Score: 2.6
CVSS Temporal Score: See <http://xforce.iss.net/xforce/xfdb/99710> for current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:H/Au:N/C:N/I:P/A:N)
CVE-ID: CVE-2014-3572
Description: OpenSSL could provide weaker than expected security. The client accepts a handshake using an ephemeral ECDH ciphersuite with the server key exchange message omitted. An attacker could exploit this vulnerability to launch further attacks on the system.
CVSS Base Score: 1.2
CVSS Temporal Score: See <http://xforce.iss.net/xforce/xfdb/99705> for current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:L/AC:H/Au:N/C:N/I:P/A:N)
CVE-ID: CVE-2014-8275
Description: OpenSSL could allow a local attacker to bypass security restrictions, caused by the modification of the fingerprint without breaking the signature. An attacker could exploit this vulnerability using non-DER or invalid encodings outside the signed portion of a certificate bypass security restrictions and perform unauthorized actions.
CVSS Base Score: 1.2
CVSS Temporal Score: See <http://xforce.iss.net/xforce/xfdb/99709> for current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:L/AC:H/Au:N/C:N/I:P/A:N)
The following IMM code levels may exhibit this issue:
The following platforms may be affected:
It’s recommended to update IMM to version 1.48 YUOOG8C or later. Firmware updates are available through IBM Fix Central - <http://www.ibm.com/support/fixcentral/> .
Disable the EXPORT cipher suites in the LDAP server side that is used by IMM.