Invalid-Curve-Ephemeral-Vulnerability-POP3/EN

Aus Siwecos
Wechseln zu: Navigation, Suche

Check for Ephemeral Invalid Curve Vulnerability

If the result is positive, there is no need for further action. If the result is negative, please read the following instructions.

Result positive Not vulnerable to Ephemeral Invalid Curve Attack attacks.
Result negativ Vulnerable to Ephemeral Invalid Curve Attack attacks.
Description The server is vulnerable to a Ephemeral Invalid Curve Attack. This allows an attacker to attack the connections.
Background Elliptic Curve Cryptography (ECC) is one of the cornerstones of modern cryptography due to its security and performance features. It is used in key exchange protocols and to calculate signatures. However, fatal security holes can occur if it is used incorrectly.
Consequence The server is vulnerable to an implementation vulnerability that allows an attacker to decrypt the communication.
Solution/Tips If vulnerability has been reported, immediately install an update to your TLS implementation on your server.