Vulnerability Bulletins

Security Bulletin: DTLS Secure Real-time Transport Protocol (SRTP) vulnerabilities in OpenSSL affect Juniper EX Series Network Switches (CVE-2014-3513, CVE-2014-3567, CVE-2014-3568)

   
Affected software IBM
 
OpenSSL vulnerabilities along with SSL 3 Fallback protection (TLS_FALLBACK_SCSV) were disclosed on October 15, 2014 by the OpenSSL Project. OpenSSL is used by Juniper EX Series Network Switches sold by IBM for use in IBM Products. Juniper EX Series Network Switches has addressed the applicable CVEs and included the SSL 3.0 Fallback protection (TLS_FALLBACK_SCSV) provided by OpenSSL. CVE(s): CVE-2014-3513, CVE-2014-3567 and CVE-2014-3568 Affected product(s) and affected version(s):

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_dtls_secure_real_time_transport_protocol_srtp_vulnerabilities_in_openssl_affect_juniper_ex_series_network_switches_cve_2014_3513_cve_2014_3567_cve_2014_3568?lang=en_us