Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
CPnoob
Contributor

Renegotiation DoS Vulnerability

I got a scan report of my ip address.

Content of the report is:
The flaw exists because the remote SSL/TLS service does not properly restrict client-initiated renegotiation within the SSL and TLS protocols.
Note: The referenced CVEs are affecting OpenSSL and Mozilla Network Security Services (NSS) but both are in a DISPUTED state with the following rationale:
> It can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment.
Both CVEs are still kept in this VT as a reference to the origin of this flaw.
Detection method
Checks if the remote service allows to re-do the same SSL/TLS handshake (Renegotiation) over an existing / already established SSL/TLS connection.
Evidence
Address
https://xxx.xxx.net/ The following indicates that the remote SSL/TLS service is affected:
Protocol Version | Successful re-done SSL/TLS handshakes (Renegotiation) over an existing / already established SSL/TLS connection
TLSv1.2 | 10
Solution
Users should contact their vendors for specific patch information.
A general solution is to remove/disable renegotiation capabilities altogether from/in the affected SSL/TLS service. VendorFix

 

And the ref. to SSL/TLS: Renegotiation DoS Vulnerability (CVE-2011-1473, CVE-2011-5094)

I can't find a way to disable Client-Initiated Renegotiation.

0 Kudos
1 Reply
Lesley
Advisor

CVE-2011-5094: 

Not related to Check Point:

https://nvd.nist.gov/vuln/detail/CVE-2011-5094#vulnCurrentDescriptionTitle

CVE-2011-1473: 

Not exploitable, as Check Point puts all sorts of protections against DoS on the gateway (limiting the number of connections, limiting the amount of data, etc.) and this CVE is not even considered a vulnerability in OpenSSL by the community.
-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events