Vulnerability Bulletins

Security Bulletin: Vulnerabilities in OpenSSL affect IBM System Networking RackSwitch (CVE-2014-3570, CVE-2014-3572, CVE-2014-8275, CVE-2015-0204)

   
Affected software IBM
 
OpenSSL vulnerabilities were disclosed on January 8, 2015 by the OpenSSL Project. This includes "FREAK: Factoring Attack on RSA-EXPORT keys" TLS/SSL client and server vulnerability. OpenSSL is used by IBM System Networking RackSwitch. The IBM System Networking Switches listed below have addressed the applicable CVEs. CVE(s): CVE-2014-3570, CVE-2014-3572, CVE-2014-8275 and CVE-2015-0204 Affected product(s) and affected version(s): Product Affected version IBM System

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_vulnerabilities_in_openssl_affect_ibm_system_networking_rackswitch_cve_2014_3570_cve_2014_3572_cve_2014_8275_cve_2015_0204?lang=en_us