SafeConsole and SafeConsoleReady Devices Not Affected by OpenSSL Heartbleed Vulnerabillity
Recently a security vulnerability in the OpenSSL cryptography library was discovered.
SafeConsole and the SafeConsoleReady Devices are not affected by the Heartbleed security vulnerability.
The SafeConsoleReady device software uses OpenSSL but remains unaffected. The device software is protected from the Heartbleed vulnerability specifically by using certificate pinning. The protection means that an attacker cannot setup a rogue SafeConsole and modify DNS records to trick devices to connect to another server.
Read more about the OpenSSL Heartbleed vulnerability here:
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0160