---
title: Hundreds of cloud apps still vulnerable to DROWN
description: Hundreds of cloud apps still vulnerable to DROWN
---

[![TowerWall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/head-logo-2.svg "TowerWall")](https://towerwall.com/)

[![TowerWall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/towerwall-logo-white-test.svg "TowerWall")](https://towerwall.com/)

- [Our Partners](https://towerwall.com/how-we-protect-you/our-technology-partners/)
- Our Solutions 
    - - Our Cybersecurity Solutions 
                  - We operationalize infosec,  
                     building security solutions that  
                     safeguard your most critical assets.
          - - [Solutions Overview](https://towerwall.com/cybersecurity-solutions/)
                  - [Risk Assessments & Security Reviews](https://towerwall.com/cybersecurity-solutions/risk-assessments-security-reviews/)
                  - [Program & Policy Development](https://towerwall.com/cybersecurity-solutions/program-policy-development/)
                  - [Incident Response & Remediation](https://towerwall.com/cybersecurity-solutions/incident-response-remediation/)
                  - [Managed Detection & Response](https://towerwall.com/cybersecurity-solutions/managed-detection-response/)
          - - [Compliance & Privacy](https://towerwall.com/cybersecurity-solutions/compliance-privacy/)
                  - [Comprehensive Security Training](https://towerwall.com/cybersecurity-solutions/comprehensive-security-training/)
                  - [Vulnerability Protection](https://towerwall.com/cybersecurity-solutions/vulnerability-protection/)
                  - [Penetration Testing](https://towerwall.com/cybersecurity-solutions/penetration-testing/)
- Virtual Security Officers 
    - - Virtual Security Officer 
                  - Leverage the experience and  
                     security acumen of Towerwall’s  
                     on-demand security experts.
          - - [Virtual Chief Information Security Officer (VCISO)](https://towerwall.com/virtual-security-officers/virtual-chief-information-security-officer-vciso/)
                  - [Virtual Data Protection Officer (vDPO)](https://towerwall.com/virtual-security-officers/virtual-data-protection-officer-vdpo/)
                  - [Virtual Chief Privacy Officer (vCPO)](https://towerwall.com/virtual-security-officers/virtual-chief-privacy-officer-vcpo/)
- We Advise 
    - - We Advise 
                  - One-size security solutions only  
                     lead to failure.
          - Industries 
                  - [Higher Education](https://towerwall.com/industries/higher-education/)
                  - [Financial Services & Banking](https://towerwall.com/industries/financial-services-banking/)
                  - [Healthcare](https://towerwall.com/industries/healthcare/)
                  - [BioPharma & Bio-Therapeutics](https://towerwall.com/industries/biopharma-bio-therapeutics/)
                  - [Retail](https://towerwall.com/industries/retail/)
                  - [Government](https://towerwall.com/industries/government/)
                  - [Catholic Diocese](https://towerwall.com/industries/catholic-diocese-cybersecurity/)
                  - [Cannabis](https://towerwall.com/industries/cannabis/)
                  - [Small Business](https://towerwall.com/industries/small-business/)
                  - [Enterprise](https://towerwall.com/industries/enterprise/)
          - Trends & Threats 
                  - [Remote Workforce](https://towerwall.com/trends-threats/remote-workforce/)
                  - [Vendor Questionnaire](https://towerwall.com/trends-threats/vendor-questionnaire/)
                  - [HIPAA](https://towerwall.com/trends-threats/hipaa/)
                  - [Ransomware](https://towerwall.com/trends-threats/ransomware/)
                  - [GDPR](https://towerwall.com/trends-threats/gdpr/)
                  - [Cloud Security](https://towerwall.com/trends-threats/cloud-security/)
                  - [Phishing](https://towerwall.com/trends-threats/phishing/)
                  - [Cybersecurity Insurance](https://towerwall.com/trends-threats/cybersecurity-insurance/)
- [Resources](https://towerwall.com/resources/) 
    - - Resources 
                  - Our latest insights, events,  
                     and tools to keep you safe.
          - - [Insights](https://towerwall.com/resources/?resources_category=MTU%3D&focusarea=0&industries=0&search=)
                  - [Webinars](https://towerwall.com/resources/?resources_category=MTg%3D&focusarea=0&industries=0&search=)
                  - [Whitepapers](https://towerwall.com/resources/?resources_category=MTY%3D&focusarea=0&industries=0&search=)
                  - [View All](https://towerwall.com/resources/)
- [Company](https://towerwall.com/company/) 
    - - Our Company 
                  - We are the industry’s leading cybersecurity preparedness partner.
          - - [Who We Are](https://towerwall.com/company/)
                  - [Our Team](https://towerwall.com/company/our-team/)
                  - [Our Approach](https://towerwall.com/our-approach/)
                  - [Our Values](https://towerwall.com/company/our-values/)
          - - [Awards & Recognition](https://towerwall.com/company/awards-recognition/)
                  - [Certifications & Affiliations](https://towerwall.com/company/certifications-affiliations/)
                  - [Community Involvement](https://towerwall.com/company/community-involvement/)
                  - [Careers](https://towerwall.com/company/careers/)
                  - [Contact Us](https://towerwall.com/company/contact-us/)

Topics  SSLv2, CISO, DROWN vulnerability, FREAK, DROWN, HTTPS, cannabis, Enterprise

# Hundreds of cloud apps still vulnerable to DROWN

[By Michelle Drolet](https://blog.towerwall.com/author/towerwall2020)

[Read More](https://blog.towerwall.com/author/towerwall2020)

 2 Minute Read

March 22, 2016

## Complacency in addressing known vulnerabilities puts users at risk

If you have even a passing interest in security vulnerabilities, there’s no chance that you missed the news about the [DROWN vulnerability](http://www.networkworld.com/article/3041419/security/drown-attack-sinks-security-for-millions-of-websites.html). It’s one of the biggest vulnerabilities to hit since Heartbleed, potentially impacting a third of all HTTPS websites. By exploiting the obsolete SSLv2 protocol, this flaw makes it possible for an attacker to eavesdrop on a TLS session.  
 Because we use SSL and TLS encryption to shop, send messages, and send emails online, DROWN potentially allows attackers to access our messages, passwords, credit card details, and other sensitive data.  
 DROWN was disclosed on March 1, but a full week later [Netskope](https://resources.netskope.com/h/i/221538492-drown-vulnerability-remains-high) identified 676 SaaS applications that were still vulnerable to the attack. This highlights a recurring problem we see time and time again in the security industry -- a failure to remediate vulnerabilities.  
 Detecting issues is only the first step, companies must take action to close loopholes and protect their customers.

Interestingly, Netskope also pointed out that of those 676 SaaS apps, 73 are also still vulnerable to FREAK, 42 are still vulnerable to Logjam, and 38 are still vulnerable to OpenSSL CCS attack.  
 The longer it takes to deal with a known vulnerability, the higher your risk of a successful attack. [Known vulnerabilities still pose the biggest IT security threats](http://www.networkworld.com/article/2896785/security0/known-issues-pose-biggest-it-security-threats.html), and there’s little sign that’s going to change any time soon.  
 We saw the same pattern of complacency after the Heartbleed vulnerability was unveiled. A full year later, 74% of Global 2000 companies with public-facing systems vulnerable to Heartbleed had failed to remediate the problem across all servers, according to security firm, [Venafi](https://www.venafi.com/offers/most-global-2000-have-not-fully-remediated-heartbleed).  
 Netskope has been posting daily updates on DROWN, and it’s clear that some companies are taking action, but as of March 14, two weeks after the disclosure, there are still 513 vulnerable apps.

### **Dealing with DROWN**

There has been some disagreement about how easy it is to exploit DROWN, but it’s certainly a potentially serious vulnerability that’s worth addressing. You can check to see whether your own website is vulnerable by visiting the [DROWN Attack website](https://drownattack.com/).  
 It’s also not especially difficult to remediate, simply don’t allow SSLv2 on any of your servers, and ensure that private keys are not being used anywhere with server software that allows SSLv2 connections. This is an obsolete protocol that should have already been removed due to its inherent weaknesses.  
 Vulnerabilities like DROWN and FREAK really highlight the dangers of obsolete cryptography. This is something we should all be taking more seriously.  
 There’s a real need to break down department barriers, so that threats can be dealt with efficiently and in a timely fashion. The latest [IT Security and Operations Survey](http://www.bmc.com/info/secops-survey.html) from BMC and Forbes Insights, found that 44% of data breaches in the U.S. and Europe are caused by known vulnerabilities. The report lays the blame on a disconnect between security and IT operations teams, which often have different goals and priorities. Lack of communication, coordination, and proper oversight is disastrous for data security.  
 It’s up to CIOs, working with the CISO, to ensure that security and IT groups work more closely together, not just to identify issues but to fix them as quickly as possible. Organizations need to understand that these kinds of vulnerabilities are not just a theoretical concern.  
 It’s also not always possible to determine when data has been breached. It can also be difficult to categorize threats and understand their severity. But one thing is perfectly clear: burying your head in the sand and failing to deal with a known vulnerability puts your customer’s data and potentially the future of your business at serious risk.

This article was originally posted on [NetworkWorld.](http://www.networkworld.com/article/3046574/application-security/hundreds-of-cloud-apps-still-vulnerable-to-drown.html)  
*Image credit: Cutcaster*

#### Hundreds of cloud apps still vulnerable to DROWN

Back to Top

## Related Insights

### [DROWN attack sinks security for millions of websites](https://blog.towerwall.com/drown-attack-sinks-security-millions-websites)

 SSLv2, CISO, DROWN vulnerability, FREAK, DROWN, HTTPS, cannabis, Enterprise

### [Software vulnerabilities hit a record high in 2014, report says](https://blog.towerwall.com/software-vulnerabilities-hit-a-record-high-in-2014-report-says)

 SSLv2, CISO, DROWN vulnerability, FREAK, DROWN, HTTPS, cannabis, Enterprise

[View All Insights](https://blog.towerwall.com)

×

## Talk with us now about:

#### Your security needs.

- ![Phone](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/phone-icon.svg "Phone")
  
  [Call 774.204.0700](tel:774.204.0700)
- ![Mail](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/mail-icon.svg "Mail")
  
  [Email Us](mailto:info@towerwall.com)

### The front line of cybersecurity.™

For over 23 years, Towerwall, a woman-owned business, has helped scores of companies safeguard their data and leverage their investment in IT with advanced information security technology solutions and services. Our experience in all facets of information security coupled with serving in the CIO/CISO/ISO roles provides a unique first-hand understanding of the security challenges organizations face daily.

### Connect

- <https://blog.towerwall.com/info@towerwall.com>
- <https://www.linkedin.com/company/towerwall-inc.?trk=pro_other_cmpy>
- <https://twitter.com/Towerwall>
- <https://www.facebook.com/Towerwall>

- [Career Opportunities](https://towerwall.com/company/careers/)
- [Contact Us](https://towerwall.com/company/contact-us/)

© Towerwall, Inc. and its licensees. All rights reserved [Privacy Policy](http://towerwall.com/privacy-policy/) Sitemap [Created by Howbridge](https://meethowbridge.com/)

[![Towerwall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/footer-logo.svg "Towerwall")](https://towerwall.com/)