EX SSL-VPN: Is SRA EX-SSLVPN vulnerable to OpenSSL Heartbleed? How to address it?
03/26/2020 3 12527
DESCRIPTION: EX SSL-VPN: Is SRA EX-SSLVPN vulnerable to OpenSSL Heartbleed? How to address it?
SRA EX SSL-VPN
The following versions of the Aventail appliance are vulnerable to heartbleed attack.
Dell SonicWall Engineering have identified that OpenSSL Vulnerability might be affecting appliances with firmware Version 10.6.4 or 10.7.1 General/Maintenance releases. Further investigating with below data :
Its a vulnerability reported on the OpenSSL Cryptographic library and it is tracked by bug CVE-2014-0160 (based on RFC6520)
OpenSSL 1.0.1 through 1.0.1f (inclusive) are vulnerable
OpenSSL 1.0.1g is NOT vulnerable.
OpenSSL 1.0.0 branch is NOT vulnerable.
OpenSSL 0.9.8 branch is NOT vulnerable.
It has been found that appliance with firmware Versions 10.6.4 & 10.7.1 are Vulnerable to such attacks, it is recommended that these appliances need to be applied with respective hotfix to address the issue:
Platform Hotfix for Firmware Version 10.6.4 could bedownloadedhere.
Platform Hotfix for Firmware Version 10.7.0 could bedownloadedhere .
Platform Hotfix for Firmware Version 10.7.1 could bedownloadedhere.