This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Endpoints and CVE-2014-0224

  We had an audit performed and it found that our Sophos 10.3.11 endpoints were vulnerable to the CVE-2014-0224 man in the middle attack on  ecmnet (8194/tcp)   http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224    http://www.securityfocus.com/bid/67899   I think the scan was done using OpenVAS.

I need to show that we aren't really vulnerable and *WHY*.   Or if we are, what is the plan to fix it.   Can you guys help me out with this?  

:55223


This thread was automatically locked due to age.
Parents
  • I believe that both the "server" and "client" need to vulnerable?  Is the server on RMS 4 and the client on RMS3?  In which case I think you are OK.  One to check with the Support I suspect.

    Regards,

    Jak

    :55300
Reply
  • I believe that both the "server" and "client" need to vulnerable?  Is the server on RMS 4 and the client on RMS3?  In which case I think you are OK.  One to check with the Support I suspect.

    Regards,

    Jak

    :55300
Children
No Data