A vulnerability has been reported against virtually all versions of OpenSSL stating that client-initiated renegotiation is not properly restricted within the SSL and TLS protocols. This might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection. Some network services in Network and Security Manager (NSM) utilizing SSL/TLS were found vulnerable to this issue. This issue has been assigned CVE-2011-1473.
Network services in NSM utilizing SSL/TLS have been fixed to resolve this vulnerability. NSM Releases containing the fix specifically include:
Use access lists or firewall filters to limit access to NSM from only trusted networks.