cancel
Showing results for 
Search instead for 
Did you mean: 
dw98
Level 7

McAfee vulnerability scanner to detect SSLv2 or DROWN attack

Please advise for vulnerability manager 7.5,

Please advise how would the McAfee vulnerability scanner would be able to detect SSLv2 or DROWN attack based on http://www.kb.cert.org/vuls/id/583776

How would this finding be flagged in the vulnerability manager report?

How can we verify if the detection from the scanner can be false positive?

4 Replies
dw98
Level 7

Re: McAfee vulnerability scanner to detect SSLv2 or DROWN attack

Hi,

can anyone please assist to advise on this?

0 Kudos
sunilgmanj
Level 7

Re: McAfee vulnerability scanner to detect SSLv2 or DROWN attack

is ePO affected by it ?

0 Kudos
dw98
Level 7

Re: McAfee vulnerability scanner to detect SSLv2 or DROWN attack

can anyone please advise?

0 Kudos
kapilpradhan
Level 7

Re: McAfee vulnerability scanner to detect SSLv2 or DROWN attack

For Drown,

Create vulns set contain faultlineid = 19727

For SSLV3  and TLS 1.0

Create vulns set contain faultlineid = 11418

8242 will detect if SSL is being utilized by webserver.

I am also trying find faultlineid for SSLv2, so far I do not have any luck

Hope this help