204.124.92.195

Regular View Raw Data
Last Seen: 2024-05-09

GeneralInformation

Hostnames blm.gov
www.adoptahorse.blm.gov
afs.ak.blm.gov
fire.ak.blm.gov
sdms.ak.blm.gov
www.ak.blm.gov
www.az.blm.gov
www.birdsofprey.blm.gov
www.co.blm.gov
www.fire.blm.gov
www.glorecords.blm.gov
www.idahofireinfo.blm.gov
www.landscape.blm.gov
web.mt.blm.gov
glorecords.navigator.blm.gov
www.nm.blm.gov
www.ntc.blm.gov
www.nv.blm.gov
opac.blm.gov
www.opac.blm.gov
afmss.training.blm.gov
www.ut.blm.gov
www.wildhorseandburro.blm.gov
www.wy.blm.gov
Domains blm.gov 
Country United States
City Denver
Organization Bureau of Land Management
ISP U.S. Department of the Interior
ASN AS22284

Vulnerabilities

Note: the device may not be impacted by all of these issues. The vulnerabilities are implied based on the software and version.

CVE-2019-0190 5.0A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts.
CVE-2009-3767 4.3libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
CVE-2009-3766 6.8mutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
CVE-2009-3765 6.8mutt_ssl.c in mutt 1.5.19 and 1.5.20, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
CVE-2009-1390 6.8Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the chain is accepted instead of verifying the entire chain, which allows remote attackers to spoof trusted servers via a man-in-the-middle attack.

OpenPorts

1615890568 | 2024-05-09T01:26:52.950224
  
443 / tcp



Contact Us

Shodan ® - All rights reserved