Acunetix - TLS 1.0 enabled
Target URL | https://egov.quangnam.gov.vn |
Severity | Medium |
Affects
Attack Details
The SSL server (port: 443) encrypts traffic using TLSv1.0.
HTTP Request
Vulnerability Description
The web server supports encryption through TLS 1.0. TLS 1.0 is not considered to be "strong cryptography" as defined and required by the PCI Data Security Standard 3.2(.1) when used to protect sensitive information transferred to or from web sites.
According to PCI, "30 June 2018 is the deadline for disabling SSL/early TLS and implementing a more secure encryption protocol – TLS 1.1 or higher (TLS v1.2 is strongly encouraged) in order to meet the PCI Data Security Standard (PCI DSS) for safeguarding payment data.
Impact
An attacker may be able to exploit this problem to conduct man-in-the-middle attacks and decrypt communications between the affected service and clients.
Remediation
It is recommended to disable TLS 1.0 and replace it with TLS 1.2 or higher.
ReferencesAre You Ready for 30 June 2018? Saying Goodbye to SSL/early TLS
PCI 3.1 and TLS 1.2 (Cloudflare Support)