[R1] Industrial Security 1.1.0 Fixes One Third-party Vulnerability

Related Vulnerabilities: CVE-2017-3738   CVE-2018-0733   CVE-2018-0739  

Industrial Security leverages third-party software to help provide underlying functionality. One of the third-party components (OpenSSL) were found to contain vulnerabilities, and updated versions have been made available by the providers. Out of caution and in line with good practice, Tenable opted to upgrade the bundled OpenSSL to address the potential impact of these issues. Industrial Security 1.1.0 updates OpenSSL to version 1.0.2o to address the identified vulnerabilities.

Synopsis

Industrial Security leverages third-party software to help provide underlying functionality. One of the third-party components (OpenSSL) were found to contain vulnerabilities, and updated versions have been made available by the providers.

Out of caution and in line with good practice, Tenable opted to upgrade the bundled OpenSSL to address the potential impact of these issues. Industrial Security 1.1.0 updates OpenSSL to version 1.0.2o to address the identified vulnerabilities.

Solution

Tenable has released Industrial Security 1.1.0 to address this issue. The new version can be obtained from the Tenable Download Page (https://www.tenable.com/downloads/industrial-security).