Weak Encryption Flaw in Novell NetWare 6.5 and Open Enterprise Server
CVE-2006-0999

Currently unrated

Key Information:

Vendor
Novell
Vendor
CVE Published:
23 March 2006

Summary

The SSL server implementation within Novell NetWare 6.5 and Novell Open Enterprise Server (OES) is susceptible to a weakness where a client can compel the server to negotiate weak encryption protocols. This occurs when a client signals that it requires a weak cipher for compatibility, which could enable attackers to decrypt sensitive data transmitted over an SSL protected session, posing a significant risk to the confidentiality and integrity of communications.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.