cisco-sa-20160129-openssl

Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products

High · Updated · Cisco

68 products with CSAF evidence

On January 28, 2016, the OpenSSL Project released a security advisory detailing two vulnerabilities. Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to conduct man-in-the-middle attacks on an SSL/TLS connection. This advisory will be updated as additional information becomes available. Cisco will release software updates that address these vulnerabilities. Workarounds that address these vulnerabilities are not available.