Description
SSL version 2 is known to have numerous security vulnerabilities, rendering it highly insecure and susceptible to attacks.
Recommendation
To mitigate security risks, disable SSL 2 and transition to more secure protocols such as TLS 1.2 or TLS 1.3.
References
- OWASP: Transport Layer Protection Cheat Sheet
- RFC 6176: Prohibiting Secure Sockets Layer (SSL) Version 2.0
- CWE-16
- CWE-326
- OWASP 2021-A2
- OWASP 2021-A5
Related Issues
- BREACH attack - CVE-2013-3587
- SSL 3 enabled - Vulnerability
- CRIME (SPDY) attack - CVE-2012-4930
- CRIME (SSL/TLS) attack - CVE-2012-4929
- Tags:
- SSL/TLS
- Encryption
- Server Misconfiguration
Anything's wrong? Let us know Last updated on May 13, 2024