OpenSSL project has issued a security advisory and released critical updates to patch several vulnerabilities on the June 5th 2014.
The update included a fix for:
• (CVE-2014-0224) - SSL/TLS MITM vulnerability
Summary of Issue:
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability. For more details about this security vulnerability see, http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0224
CVE-2014-0224 requires both ends of the connection to be compromised for an intruder to exploit this security vulnerability.
NetVault Backup 10.0
As long as users connect to the NetVault Web UI console via a supported Web Browser interface there is no risk. Currently supported NetVault 10 web browsers do *not* use OpenSSL. NetVault supported Web browsers are Internet Explorer, Firefox, Chrome on Desktop and iOS, and Safari. For specific Web Browser version support please consult the NetVault Backup Compatibility Guide. However, to ensure highest level of security, it is recommended customers upgraded to NetVault 10.0.1 when it is released approximately in September 2014. Please see the below chart for Recommended actions.
NetVault SmartDisk
Support for SSL connections has been added to NetVault SmartDisk, but SSL connections have never been enabled for communication with NetVault Backup. Thus, NetVault SmartDisk is not at risk to this vulnerability. However, similar to NetVault Backup, to ensure highest level of security it is recommended customers upgraded to NetVault SmartDisk 10.0.0 when it is released.
NetVault Backup (Core) | 10.0 |
Impact | Versions above are affected and should be updated. |
Recommended Action | Update to 10.0.1 (when available) |
NetVault Backup (Core) | 9.x and 8.x |
Impact | Not affected |
NetVault SmartDisk | 2.0.x, 1.6.x |
Impact | Not affected |