Id |
Log ID |
Jvninfo Id |
Plugin ID |
CVE |
CVSS |
Risk |
Host |
Protocol |
Port |
Name |
Synopsis |
Description |
Solution |
See Also |
Plugin Output |
Actions |
51151 |
H28_MUN_DWEB_Q4_172_16_240_seg.csv |
46189 |
62565 |
CVE-2012-4929 |
4.3 |
Medium |
172.16.240.115 |
tcp |
443 |
Transport Layer Security (TLS) Protocol CRIME Vulnerability |
The remote service has a configuration that may make it vulnerable to
the CRIME attack. |
The remote service has one of two configurations that are known to be
required for the CRIME attack :
- SSL / TLS compression is enabled.
- TLS advertises the SPDY protocol earlier than version 4.
Note that Nessus did not attempt to launch the CRIME attack against the
remote service. |
Disable compression and / or the SPDY service. |
http://www.iacr.org/cryptodb/data/paper.php?pubkey=3091
https://discussions.nessus.org/thread/5546
http://www.nessus.org/u?8ec18eb5
https://issues.apache.org/bugzilla/show_bug.cgi?id=53219 |
The following configuration indicates that the remote service may be vulnerable to the CRIME attack : - SSL / TLS compression is enabled. |
|
51952 |
H28_MUN_DWEB_Q4_172_16_240_seg.csv |
46189 |
62565 |
CVE-2012-4929 |
4.3 |
Medium |
172.16.240.131 |
tcp |
443 |
Transport Layer Security (TLS) Protocol CRIME Vulnerability |
The remote service has a configuration that may make it vulnerable to
the CRIME attack. |
The remote service has one of two configurations that are known to be
required for the CRIME attack :
- SSL / TLS compression is enabled.
- TLS advertises the SPDY protocol earlier than version 4.
Note that Nessus did not attempt to launch the CRIME attack against the
remote service. |
Disable compression and / or the SPDY service. |
http://www.iacr.org/cryptodb/data/paper.php?pubkey=3091
https://discussions.nessus.org/thread/5546
http://www.nessus.org/u?8ec18eb5
https://issues.apache.org/bugzilla/show_bug.cgi?id=53219 |
The following configuration indicates that the remote service may be vulnerable to the CRIME attack : - SSL / TLS compression is enabled. |
|
56731 |
H28_DWEB_NW_Scan_Q1_172_16_240_Seg_20160518_hepxqa.csv |
46189 |
62565 |
CVE-2012-4929 |
4.3 |
Medium |
172.16.240.115 |
tcp |
443 |
Transport Layer Security (TLS) Protocol CRIME Vulnerability |
The remote service has a configuration that may make it vulnerable to
the CRIME attack. |
The remote service has one of two configurations that are known to be
required for the CRIME attack :
- SSL / TLS compression is enabled.
- TLS advertises the SPDY protocol earlier than version 4.
Note that Nessus did not attempt to launch the CRIME attack against the
remote service. |
Disable compression and / or the SPDY service. |
http://www.iacr.org/cryptodb/data/paper.php?pubkey=3091
https://discussions.nessus.org/thread/5546
http://www.nessus.org/u?8ec18eb5
https://issues.apache.org/bugzilla/show_bug.cgi?id=53219 |
The following configuration indicates that the remote service may be vulnerable to the CRIME attack : - SSL / TLS compression is enabled. |
|
57528 |
H28_DWEB_NW_Scan_Q1_172_16_240_Seg_20160518_hepxqa.csv |
46189 |
62565 |
CVE-2012-4929 |
4.3 |
Medium |
172.16.240.131 |
tcp |
443 |
Transport Layer Security (TLS) Protocol CRIME Vulnerability |
The remote service has a configuration that may make it vulnerable to
the CRIME attack. |
The remote service has one of two configurations that are known to be
required for the CRIME attack :
- SSL / TLS compression is enabled.
- TLS advertises the SPDY protocol earlier than version 4.
Note that Nessus did not attempt to launch the CRIME attack against the
remote service. |
Disable compression and / or the SPDY service. |
http://www.iacr.org/cryptodb/data/paper.php?pubkey=3091
https://discussions.nessus.org/thread/5546
http://www.nessus.org/u?8ec18eb5
https://issues.apache.org/bugzilla/show_bug.cgi?id=53219 |
The following configuration indicates that the remote service may be vulnerable to the CRIME attack : - SSL / TLS compression is enabled. |
|