Forum Discussion
apsec_200028
Nimbostratus
Apr 30, 2015Cipher Suites to Mitigate against Vulnerabilities
Hi,
I would like to know how to mitigate against the below vulnerabilites, running code version 10.2.1
TLSV1.X Poodle - CVE-2014-8730 SSLv3 Poodle - CVE-2014-3566 Beast
samstep
Cirrocumulus
Apr 30, 2015First of all - have you got the latest Hotfix for 10.2.1?
Also note that some SSL-related vulnerabilities were only patched in SSL profiles starting from v10.2.4...
Check out these articles:
https://devcentral.f5.com/articles/cve-2014-3566-poodle-vs-cve-2014-8730-tls-poodle
https://devcentral.f5.com/articles/cve-2014-3566-poodle-vs-cve-2014-8730-tls-poodle
You can check how good your cipher config is using the SSL Labs test your websites: https://www.ssllabs.com/ssltest/
Hope this helps,
Sam
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects