RSA BSAFE Micro Edition Suite CVE-2014-0636 Chain Processing Vulnerability
BID:66791
Info
RSA BSAFE Micro Edition Suite CVE-2014-0636 Chain Processing Vulnerability
| Bugtraq ID: | 66791 |
| Class: | Design Error |
| CVE: |
CVE-2014-0636 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2014 12:00AM |
| Updated: | Jan 12 2015 12:03AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
RSA BSAFE Micro Edition Suite CVE-2014-0636 Chain Processing Vulnerability
RSA BSAFE Micro Edition Suite is prone to a chain-processing vulnerability due to incorrect certificate chain processing logic.
Successfully exploiting this issue allows attackers to create improper authenticated SSL connections, which will aid in further attacks.
RSA BSAFE Micro Edition Suite (MES) 4.0.x versions prior to 4.0.5 and 3.2.x version prior to 3.2.6 are vulnerable.
RSA BSAFE Micro Edition Suite is prone to a chain-processing vulnerability due to incorrect certificate chain processing logic.
Successfully exploiting this issue allows attackers to create improper authenticated SSL connections, which will aid in further attacks.
RSA BSAFE Micro Edition Suite (MES) 4.0.x versions prior to 4.0.5 and 3.2.x version prior to 3.2.6 are vulnerable.
Exploit / POC
RSA BSAFE Micro Edition Suite CVE-2014-0636 Chain Processing Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
RSA BSAFE Micro Edition Suite CVE-2014-0636 Chain Processing Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information
Solution:
Updates are available. Please see the references or vendor advisory for more information
References
RSA BSAFE Micro Edition Suite CVE-2014-0636 Chain Processing Vulnerability
References:
References: