Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-217 — Exploiting Incorrectly Configured SSL/TLS
CAPEC-217

Exploiting Incorrectly Configured SSL/TLS

TLP:CLEAR

Description

Likelihood of attack: Low. An adversary takes advantage of incorrectly configured SSL/TLS communications that enables access to data intended to be encrypted. The adversary may also use this type of attack to inject commands or other traffic into the encrypted stream to cause compromise of either the client or server.

Mitigation

Do not use SSL, as all SSL versions have been broken and should not be used. If TLS is not an option for the client or server, consider setting timeouts on SSL sessions to extremely low values to lessen the potential impact. | Only use TLS version 1.2+, as versions 1.0 and 1.1 are insecure. | Configure TLS to use secure algorithms. The current recommendation is to use ECDH, ECDSA, AES256-GCM, and SHA384 for the most security.

Details

Platforms
Communications
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.