10-19-2017 03:44 AM - edited 03-08-2019 07:26 PM
Hi all,
how can i review what version of OPENSSL is being used and is it safe or need an upgrade.
Many thanks
MM
Solved! Go to Solution.
12-19-2017 08:04 AM
resolved the issue, had to upgrade the ios to 9.8.
10-19-2017 07:55 AM
Check the "Open source used in Cisco ASA..." docs on their site
Here is the one for 9.4.1
The latest suggested release is 9.4.4, at the very least you want 9.4(4)5 (has fix for CSCvd78303)
10-19-2017 08:12 AM
Hi Ken,
Many thanks for the information.
could you please advise how i can verify by using CLI or ASDM on asa what version of OpenSSL is being used and is that the correct version, and if not how to upgrade it.
Best regards,
MM
10-19-2017 08:15 AM
10-19-2017 08:25 AM
Many thanks Ken
10-20-2017 01:48 AM
Hi Ken,
this is the below report we have got for pen test
OpenSSL was outdated. A suitably placed attacker may be able to decrypt or forge SSL messages by telling the service to begin encrypted communications before key material has been exchanged, which causes predictable keys to be used for future communications. SSL-Session: Protocol
Update the OpenSSL encryption library to the latest available version. Tools such as NMAP (using the script ‘-p- --script=ssl-ccs-injection’) may be used to verify this issue.
what procedure should i follow to comply with this issue
Please advise
Many thanks
MM
10-20-2017 03:51 AM
12-19-2017 08:04 AM
resolved the issue, had to upgrade the ios to 9.8.
04-18-2022 10:58 AM
Hello,
Just run this command from cli
openssl version
openssl version –help
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide