QID 38863
Date Published: 2022-05-16
QID 38863: Weak SSL/TLS Key Exchange
The SSL/TLS server supports key exchanges that are cryptographically weaker than recommended. Key exchanges should provide at least 224 bits of security, which translates to a minimum key size of 2048 bits for Diffie Hellman and RSA key exchanges.
An attacker with access to sufficient computational power might be able to recover the session key and decrypt session content.
Solution
Change the SSL/TLS server configuration to only allow strong key exchanges.
Vendor References
CVEs related to QID 38863
Software Advisories
| Advisory ID | Software | Component | Link |
|---|