{}

브랜드

Impact-Company-Logo-English Black-01-177x54

슈나이더 일렉트릭 코리아 웹사이트에 방문해 주셔서 감사합니다.

슈나이더 일렉트릭 코리아 웹사이트 방문자 분들 모두 환영합니다.

FAQ 검색

Is PowerChute Vulnerable to CVE-2011-3389?

Issue:
PowerChute is being flagged as Vulnerable to BEAST SSL security issue.

Products:
PowerChute Business Edition 9.1.0, 9.1.1
PowerChute Network Shutdown versions 3.0.0, 3.0.1, 3.1

Environment:
All supported OS

Cause:
**The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.

Solution:

Upgrade PowerChute Business Edition to version 9.5 or above Or uninstall PowerChute Business Edition and install PowerChute Serial Shutdown.
Upgrade PowerChute Network Shutdown to version 4.x or 5.x
Or
Upgrade browser to use a version that allows for TLS 1.2 support - disable SSL 2.0/3.0 and TLS 1.0/1.1 when accessing PowerChute UI.

** Information provided by National Vulnerability Database http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3389

슈나이더 일렉트릭 Korea

자세히 알아보기
제품군
PowerChute Network ShutdownPowerChute Business Edition
카테고리:
Software
자세히 알아보기
제품군
PowerChute Network ShutdownPowerChute Business Edition
카테고리:
Software