092 – Insecure encryption algorithm - Anonymous cipher suites
Description
The application allows connections with anonymous cipher suites.
Impact
Obtain sensitive information by performing a MitM attack.
Recommendation
Use algorithms considered cryptographically secure.
Threat
Unauthorized attacker from adjacent network performing a MitM attack.
Expected Remediation Time
Score 4.0
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
- Attack vector: N
- Attack complexity: L
- Attack Requirements: N
- Privileges required: N
- User interaction: N
- Confidentiality (VC): H
- Integrity (VI): N
- Availability (VA): N
- Confidentiality (SC): N
- Integrity (SI): N
- Availability (SA): N
Threat 4.0
- Exploit maturity: X