How does OpenSSL used in Smart Scan integrated products?
Smart Scan integrated products communicates over a secure traffic encrypted by OpenSSL, and uses the generic steps below to establish a secure connection between two entities:
- TCP 3-way handshake
- SSL handshake
- Send application data
Why is it low risk?
Aside from the fact that the communication traffic contains only server SSL public key and uninterpretable CRC values, this vulnerability cannot be leveraged since the heartbeat check packet is controlled by our program. It is also difficult to tamper the heartbeat packet and control the payload variable to get the memory block from our product.
What are the products integrated with Smart Scan?
- House Call 8.0 - Fixed via Active Update (AU)
- InterScan Messaging Security Suite (IMSS) for Linux 7.1 SP1 - Critical patch will be released on May 15
- InterScan Messaging Security Virtual Appliance (IMSVA) 8.5 and 8.5 SP1 - Critical patch will be released on May 15
- OfficeScan (OSCE) 11.0 - Critical patch is released on May 10
- Titanium 7.0 and 7.2 - Fixed via Active Update (AU)
- Worry Free Business Security (WFBS) 9.0 - GM package will be repacked on May 6