Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

[R7] OpenSSL '20151203' Advisory Affects Tenable SecurityCenter

Medium

Synopsis

SecurityCenter and the Tenable Appliance are potentially impacted by vulnerabilities in OpenSSL that were recently disclosed and fixed. Note that due to the time involved in doing a full analysis of the issue, Tenable has opted to patch the included version of OpenSSL as a precaution, and to save time.

  • CVE-2015-3194 - crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function parameter. (SecurityCenter)
  • CVE-2015-3195 - The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application. (3.x Appliance)
  • CVE-2015-7575 - The Transport Layer Security (TLS) protocol contains a flaw that is due to the program accepting RSA-MD5 signatures in the server signature within the TLS 1.2 ServerKeyExchange messages. This may allow a remote attacker to theoretically conduct collision-based forgery attacks. (3.x Appliance)

Based on a very cursory examination, it is believed that SecurityCenter is not impacted by CVE-2015-3195 or CVE-2015-3196, which were also fixed in this OpenSSL release. Regardless, this patch resolves those issues as well.

Based on Developer input, the Tenable Appliance 3.x.y releases were affected by CVE-2015-3195 and CVE-2015-7575. The Tenable Appliance 4.0.0 release is not affected by CVE-2015-3194, CVE-2015-3195, CVE-2015-3196 and CVE-2015-7575.

Please note that Tenable strongly recommends that Tenable products be installed on a subnet that is not Internet addressable.

Solution

Nessus

Tenable has released a patch for all supported versions of SecurityCenter that addresses this vulnerability. This patch applies OpenSSL 1.0.1q, which is not affected. This patch has been tested on SecurityCenter versions 4.6.2.2, 4.7.1, 4.8.2, 5.0.0.1, 5.0.2, and 5.1.0. Additionally, SecurityCenter 5.2.0 was released on December 16, 2015, which includes OpenSSL 1.0.1.q and is a recommended mitigation, as it also brings a plethora of enhancements and features that are sure to delight. Upgrade information can be obtained from:

http://static.tenable.com/prod_docs/upgrade_security_center.html

The patch can be obtained from:

https://support.tenable.com/support-center/index.php?x=&mod_id=160

File	   		      md5sum
SC-201601.1-4.x-rh5-32.tgz    87723711f52f1c22279a1597c445e387 
SC-201601.1-4.x-rh5-64.tgz    658fd17c6ee435f99612b72958da8170
SC-201601.1-4.x-rh6-32.tgz    ca9876612e3646d55ff455e3b614b08a
SC-201601.1-4.x-rh6-64.tgz    ff9027d2315bba4650d74d3a9d723765
SC-201601.1-5.x-rh5-64.tgz    4f7a4666232874226345589000c92edd
SC-201601.1-5.x-rh6-64.tgz    1ffc0779572997a753e575acc6d7772b

Tenable Appliance

Tenable Appliance users can upgrade to version 3.10.0 or 4.0.0, which are not affected. Updates can be obtained from:

https://support.tenable.com/support-center/index.php?x=&mod_id=230

Log Correlation Engine (LCE)

Tenable has released the Log Correlation Engine (LCE) 4.8.0 that address these issues. The updated version can be found at:

https://support.tenable.com/support-center/index.php?x=&mod_id=180

This page contains information regarding security vulnerabilities that may impact Tenable's products. This may include issues specific to our software, or due to the use of third-party libraries within our software. Tenable strongly encourages users to ensure that they upgrade or apply relevant patches in a timely manner.

Tenable takes product security very seriously. If you believe you have found a vulnerability in one of our products, we ask that you please work with us to quickly resolve it in order to protect customers. Tenable believes in responding quickly to such reports, maintaining communication with researchers, and providing a solution in short order.

For more details on submitting vulnerability information, please see our Vulnerability Reporting Guidelines page.

If you have questions or corrections about this advisory, please email [email protected]

Risk Information

Tenable Advisory ID: TNS-2016-01
Risk Factor: Medium
CVSSv2 Base / Temporal Score
5.0 / 3.7
CVSSv2 Vector:
(AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)

Affected Products

SecurityCenter: 4.6.2.2, 4.7.1, 4.8.2, 5.0.0.1, 5.0.2, 5.1.0
Tenable Appliance: 3.8.0, 3.9.0
Log Correlation Engine 4.6.0, 4.6.1

Disclosure Timeline

2015-12-03 - OpenSSL upgrade released
2015-12-16 - SecurityCenter 5.2.0 released
2016-01-06 - Patches for prior supported versions released

Advisory Timeline

2016-01-06 - [R1] Initial Release
2016-01-08 - [R2] Updated with Appliance information
2016-03-03 - [R3] Title standardization
2016-03-18 - [R4] Additional Appliance information and CVEs added
2016-03-23 - [R5] Added LCE information
2016-11-15 - [R6] Adjusted CVSSv2 score
2017-02-28 - [R7] Adjust CVSS for worst-case scenario (AV:A -> AV:N)

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Try Tenable Web App Scanning

Enjoy full access to our latest web application scanning offering designed for modern applications as part of the Tenable One Exposure Management platform. Safely scan your entire online portfolio for vulnerabilities with a high degree of accuracy without heavy manual effort or disruption to critical web applications. Sign up now.

Your Tenable Web App Scanning trial also includes Tenable Vulnerability Management and Tenable Lumin.

Buy Tenable Web App Scanning

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

5 FQDNs

$3,578

Buy Now

Try Tenable Lumin

Visualize and explore your exposure management, track risk reduction over time and benchmark against your peers with Tenable Lumin.

Your Tenable Lumin trial also includes Tenable Vulnerability Management and Tenable Web App Scanning.

Buy Tenable Lumin

Contact a Sales Representative to see how Tenable Lumin can help you gain insight across your entire organization and manage cyber risk.

Try Tenable Nessus Professional Free

FREE FOR 7 DAYS

Tenable Nessus is the most comprehensive vulnerability scanner on the market today.

NEW - Tenable Nessus Expert
Now Available

Nessus Expert adds even more features, including external attack surface scanning, and the ability to add domains and scan cloud infrastructure. Click here to Try Nessus Expert.

Fill out the form below to continue with a Nessus Pro Trial.

Buy Tenable Nessus Professional

Tenable Nessus is the most comprehensive vulnerability scanner on the market today. Tenable Nessus Professional will help automate the vulnerability scanning process, save time in your compliance cycles and allow you to engage your IT team.

Buy a multi-year license and save. Add Advanced Support for access to phone, community and chat support 24 hours a day, 365 days a year.

Select Your License

Buy a multi-year license and save.

Add Support and Training

Try Tenable Nessus Expert Free

FREE FOR 7 DAYS

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Already have Tenable Nessus Professional?
Upgrade to Nessus Expert free for 7 days.

Buy Tenable Nessus Expert

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Select Your License

Buy a multi-year license and save more.

Add Support and Training