Invalid-Curve-Ephemeral-Vulnerability/EN: Unterschied zwischen den Versionen
Zeile 1: | Zeile 1: | ||
+ | |||
=== {{:{{PAGENAME}}/Headline}} === | === {{:{{PAGENAME}}/Headline}} === | ||
Aktuelle Version vom 7. Mai 2020, 11:40 Uhr
Check for the Ephemeral Invalid Curve vulnerability.
If the result is positive, there is no need for further action. If the result is negative, please read the following instructions.
Result positive | Not vulnerable to Ephemeral Invalid Curve attacks. |
Result negativ | Vulnerable by Ephemeral Invalid Curve attacks. |
Description | The server is vulnerable to an Ephemeral Invalid Curve Angriff. This allows an attacker to attack connections. |
Background | Elliptic Curve Cryptography (ECC) is one of the cornerstones of modern cryptography due to its security and performance features. It is used in key exchange protocols and to calculate signatures. However, fatal security holes can occur if it is used incorrectly. |
Consequence | The server is vulnerable through an implementation vulnerability that allows an attacker to decrypt the communication. |
Solution/Tips | If vulnerability was reported, update your TLS implementation on your server immediately. |