OpenSSL Vulnerability

Back to all Security AdvisoriesSubscribe
Security Advisories ID: 
SA12
Published Date: 
September 30, 2003
Advisory Status: 
Final
Advisory Severity: 
High

Some Blue Coat Systems products use versions of OpenSSL that are vulnerable to an attack based on malformed client certificates. The attacks can be aimed at any service on the appliance that is terminating (acting as a host for) an SSL connection. The vulnerabilities are such that disabling client certificates does not prevent the attack.

A successful attack will result in a restart of CA/SA and SG appliances, which can lead to a denial of service situation.

Workarounds: 

Restricting access to the secure management console port to trusted IP addresses may reduce exposure.

Feedback