S4E just found a high top 10 tcp port service scan
medium·SSL Controls·Updated Dec 17, 2024

SSL Logjam Vulnerability Checker

Check your SSL/TLS configuration for Logjam vulnerability. Ensure your server uses strong Diffie-Hellman key exchange parameters.

Est. Time~20 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
406
Times Used
by S4E users
261
Assets Scanned
domains & IPs
321
Vulnerabilities Found
confirmed findings
Detail

What is SSL Logjam Vulnerability?

SSL Logjam is a cryptographic vulnerability that exploits the use of weak Diffie-Hellman key exchange parameters in SSL/TLS configurations. By targeting servers that support 512-bit (export-grade) Diffie-Hellman keys, attackers can perform a man-in-the-middle (MITM) attack to decrypt encrypted communications.

The vulnerability arises from legacy cryptographic export restrictions, similar to FREAK, which required weaker encryption for certain configurations. Logjam allows attackers to downgrade the security of a connection, forcing it to use these weak parameters. Once the weak keys are broken, encrypted traffic, including sensitive data like login credentials, can be decrypted.

Mitigation involves disabling support for export-grade Diffie-Hellman ciphers, using strong (2048-bit or higher) key exchange parameters, and ensuring modern SSL/TLS configurations.

Solution Advice

To mitigate Logjam attacks, disable support for export-grade Diffie-Hellman ciphers, configure strong (2048-bit or higher) key exchange parameters, and ensure your server uses modern SSL/TLS configurations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.