Short Name |
SSL:OPENSSL-HEARTBEAT-ALTERNATE |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
SSL |
Keywords |
OpenSSL TLS DTLS Heartbeat Information Disclosure (Server, Client, and STARTTLS Support) |
Release Date |
2014/04/15 |
Update Number |
2362 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known flaw in OpenSSL. An information disclosure vulnerability exists in OpenSSL. The vulnerability is due to an error when handling TLS/DTLS heartbeat packets. An attacker can leverage this vulnerability to disclose memory contents of a connected client or server. This signature is an alternate version to SSL:OPENSSL-TLS-DTLS-HEARTBEAT that supports both clients as well as servers, including STARTTLS connections. It is, however, extremely performance impacting and could also be false-positive prone. Its use, therefore, is not recommended in a general configuration and should only be used in specific circumstances where it is required. This is a non-Recommended, performance-impacting signature. It will not be in any predefined groups. You must add this signature, by name, manually to your policy, or create your own custom dynamic group.