Vulnerability - Selection of Less-Secure Algorithm During Negotiation (Lucky 13)
search cancel

Vulnerability - Selection of Less-Secure Algorithm During Negotiation (Lucky 13)

book

Article ID: 412337

calendar_today

Updated On:

Products

CA API Gateway

Issue/Introduction

A security scan shows Vulnerability - Selection of Less-Secure Algorithm During Negotiation (Lucky 13).

"A protocol or its implementation supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties."

Environment

API Gateway 11.X

Resolution

Vulnerability CWE-757/CVE-2024-38883 is related to a specific product (Caterease). The gateway does not use this component and is not vulnerable.

Additional Information