Brocade Security Advisory ID: BSA-2014-002
Initial Publication Date: March 10, 2015
Revision: 1.7
Revision Date: April 7, 2017
Page 1
Component: OpenSSL
CVSS: 4.3
CVE-2014-3566: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3566
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses
nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain
cleartext data via a padding-oracle attack, aka the "POODLE" issue.
Impacted – Fixed in 6.7R4.
Impacted – v6.x through v7.x.
Fixed in 7.2.1d, 7.3.0c, 7.3.1, 6.4.3g, and 6.2.2g.
Impacted - Fixed in RX02800g and RX02900d.
Impacted – 10.2.02 and 11.0.00.
Impacted – 12.3.01, 12.4.0, and 12.5.1.
Fixed in 12.3.01p, 12.4.00s, and 12.5.01f.
Impacted Virtual ADX 3.0.00.
Fixed in Virtual ADX 3.1.01
Brocade Virtual Traffic Manager
(formerly Brocade SteelApp Traffic
Manager (STM))
Impacted - Disable SSL 3.0 in the global settings and all
virtual server and pool configuration files where
ssl_decrypt and ssl_encrypt are enabled. SSL 3.0 is
disabled by default on installations of version 9.9 and
later.
Brocade Services Director (formerly
SteelApp Services Controller (SSC))
Impacted - Upgrade to version 2.0 and later.
Brocade Virtual Web Application
Firewall (formerly Brocade SteelApp
Application Firewall (SAF))
Impacted – 11.0.x to 11.3.x and 12.0.x to 12.2.x.
Brocade IronView Network
Manager
Brocade Data Center Fabric
Manager