Forum Discussion
Abi80_167352
Nimbostratus
Oct 17, 2014F5 High Prio SSLv3 issue CVE-2014-3566 15102014
I am running bigip LTM version 10.2.4 and i believethis version is vulnerable to the MIM cuz of which i was adviced to switch over to TLS
My questions are
1) Does it apply to both client ...
Amit_Karnik
Nimbostratus
Oct 20, 2014We had a environment where it was not possible to update the client which was running SSL 3.0 but was possible to update the ciphers via a configuration file. A mitigation in such a situation is to disable the CBC based ciphers and leave SSL 3.0 enabled.
Note that this will mitigate CVC-2014-3566 but may be weaker if you have other weaker ciphers. Just an option in case disabling SSL 3.0 is not possible due to other constraints.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects