Errors testing new connector to CHv 8 – “Connection Error: A failure occurred connecting to Citrix Hypervisor. Error = write EPROTO 140247625111360:error:1407742E:SSL routines:SSL23_GET_SERVER_HELLO:tlsv1 alert protocol”

In the XenCenter configuration for the host, uncheck the option to force only TLS 1.2 communication. See the section, “disabling older protocols”, in the below doc.

https://www.citrix.com/content/dam/citrix/en_us/documents/white-paper/security-recommendations-when-deploying-citrix-xenserver.pdf


To correct the cert errors, when unchecking the connector setting, “ignore certificate errors”, follow the below article.

https://support.citrix.com/article/CTX261855

Related:

  • No Related Posts

Cisco Adaptive Security Appliance Software SSL VPN Denial of Service Vulnerability

A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition that prevents the creation of new SSL/Transport Layer Security (TLS) connections to an affected device.

The vulnerability is due to incorrect handling of Base64-encoded strings. An attacker could exploit this vulnerability by opening many SSL VPN sessions to an affected device. The attacker would need to have valid user credentials on the affected device to exploit this vulnerability. A successful exploit could allow the attacker to overwrite a special system memory location, which will eventually result in memory allocation errors for new SSL/TLS sessions to the device, preventing successful establishment of these sessions. A reload of the device is required to recover from this condition. Established SSL/TLS connections to the device and SSL/TLS connections through the device are not affected.

Note: Although this vulnerability is in the SSL VPN feature, successful exploitation of this vulnerability would affect all new SSL/TLS sessions to the device, including management sessions.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-asa-ssl-vpn-dos

This advisory is part of the October 2019 Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication, which includes 10 Cisco Security Advisories that describe 18 vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: October 2019 Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication.

Security Impact Rating: High

CVE: CVE-2019-12677

Related:

  • No Related Posts

Cisco IOx Application Environment Denial of Service Vulnerability

A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauthenticated, remote attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a denial of service (DoS) condition.

The vulnerability is due to a Transport Layer Security (TLS) implementation issue. An attacker could exploit this vulnerability by sending crafted TLS packets to the IOx web server on an affected device. A successful exploit could allow the attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a DoS condition.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-iox

This advisory is part of the September 25, 2019, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes 12 Cisco Security Advisories that describe 13 vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: September 2019 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication.

Security Impact Rating: High

CVE: CVE-2019-12656

Related:

  • No Related Posts

How can I disallow TLS 1.1 for the session between the user’s device and the Proxy SG?

I need a solution

Hi;

My understandins is that the TLS version setting under Configuraiton> SSL> SSL client are for the ssl session between the Proxy SG and the Server, so you can disallow TLS 1.1 between the Proxy SG and the OCS “Server”.

My question is:

How can I disallow TLS 1.1 for the session between the user’s device and the Proxy SG?

Kindly

Wasfi

0

Related:

  • No Related Posts

What’s the traffic flow in case of an inline IPS and an inline Proxy SG?

I need a solution

Hi;

If I had an IPS device connected inline with the SSL V, and next inline of the SSL V is a Proxy SG.

Does the SSL “https” stream that arrives from the Internet, does it get decrypted by the SSLV to be sent to the IPS, which in case a clean traffic, returns it to the SSLV to be encrypted again and then re-decrypted to be sent to the Proxy SG, which in turn if the traffic is allowed, sends it back to the SSLV to be encrypted again and sent to the internal “LAN”?

Kindly

Wasfi

0

Related:

  • No Related Posts