Vulnerability CVE-2015-4000

Post support questions that relate to the Windows 2003/2000/XP operating systems.

Moderators: Developers, Moderators

Post Reply
Jcsy
Posts: 2
Joined: Tue Apr 19, 2016 10:45 pm

Vulnerability CVE-2015-4000

Post by Jcsy »

Does Vulnerability CVE-2015-4000 affects Cacti ?
User avatar
micke2k
Cacti User
Posts: 261
Joined: Wed Feb 03, 2016 3:38 pm

Re: Vulnerability CVE-2015-4000

Post by micke2k »

Its usually the web server that handles the ssl. Should be IIS/Apache or Openssl that needs to be patched. Maybe the browser as well.

Centos 7 latest not vulnerable;

Name : openssl
Arch : x86_64
Epoch : 1
Version : 1.0.1e
openssl s_client -connect 127.0.0.1:443 -cipher "EDH" |grep "Server"

Server Temp Key: DH, 2048 bits
I assume that you have seen something in the IPS logs that triggered this? Try updating apache/IIS. Also affects SSH among other things.

https://www.openssl.org/blog/blog/2015/ ... g-changes/
Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest