
01 Technical background
TLS (Transport Layer Security) ensures that data is transmitted between your visitors„ browsers and your web server in an encrypted form. This is indicated by the “https” symbol and the lock icon in the address bar. Without this encryption, third parties could read or manipulate data transmitted, such as login credentials, form entries, or contact requests.
The problem is not TLS itself, but the use of outdated protocol versions. TLS 1.0 dates back to 1999, and TLS 1.1 to 2006. Both were developed with RFC 8996 officially taken out of service because they have known security flaws and no longer support modern cryptographic methods.
Nevertheless, many web servers continue to accept these versions – often for historical reasons or because existing server configurations were never adjusted. For this reason, this configuration error is one of the most common security vulnerabilities in publicly accessible web servers.
The vulnerability can usually be fixed in a few simple steps, but remains undetected for years on many systems.
02 Risks and impacts
If a server continues to support TLS 1.0 or TLS 1.1, its attack surface increases. Attackers can exploit known vulnerabilities in these protocols or, under certain conditions, attempt to downgrade a connection to an earlier version (downgrade attack). This reduces the actual level of protection of the encrypted connection.
The result could be that sensitive information such as access data or personal data is no longer transmitted with the required level of security today. Furthermore, outdated TLS versions regularly no longer meet current standards and may therefore contradict the requirements of Article 32 of the General Data Protection Regulation (GDPR), especially when personal information is transmitted, such as in a contact form.
For webshops or other applications that transmit credit card information, TLS1.3 has been mandated by regulation since 2018. Failure to comply can lead to contractual penalties, terminations by the card networks, and increased liability risks.
Even though immediate compromise of a server is not automatically possible as a result, supporting outdated protocols is considered a preventable security vulnerability and an indication of an outdated server configuration.
03 How to check the vulnerability
A first overview is provided by the free SSL Server Test by Qualys SSL Labs. The tool analyzes the publicly available TLS configuration of your server and displays it under „Configuration“ which protocol versions are supported.
If TLS 1.0 or TLS 1.1 is displayed as supported (Yes), the server configuration should be checked.
Alternatively, the configuration can be tested directly via the command line:
openssl s_client -connect their-domain.de:443 -tls1_1
If a connection is established, the server continues to accept TLS 1.1 and should be adjusted accordingly. Instead, an error message appears such as „no protocols available“ or „handshake failure“, The outdated protocol version has already been deactivated.
04 How to fix the vulnerability
The solution consists of completely disabling TLS 1.0 and TLS 1.1 on the server side and allowing only TLS 1.2 and TLS 1.3.
Depending on the server environment used, the configuration takes place at different points:
In addition, it is recommended to review the used cipher suites and adapt them to current recommendations. The relevant guidance here is the Technical Guideline BSI TR-02102-2
After each change, the TLS configuration should be retested. At the same time, it is important to ensure that legitimate users and connected systems can still access the service without any problems. In practice, almost all current browsers, operating systems, and applications today support TLS 1.2 or TLS 1.3.
FAQ
What is TLS and what is it used for?
TLS (Transport Layer Security) encrypts the data transmission between the browser and the web server. This is intended to protect, for example, login credentials, form submissions, or contact requests from being read or manipulated by third parties.
Why are TLS 1.0 and TLS 1.1 considered outdated?
TLS 1.0 and TLS 1.1 have known security vulnerabilities and no longer support modern cryptographic methods. Both protocol versions have therefore been officially retired with RFC 8996.
What risks arise from the use of outdated TLS versions?
If a server continues to support TLS 1.0 or TLS 1.1, the attack surface increases. Under certain conditions, attackers can exploit known vulnerabilities or attempt to downgrade connections to an older protocol version, which can reduce the protection level of the encrypted connection.
What is the data protection significance of outdated TLS versions?
According to the article, outdated TLS versions are regularly no longer up to date with the state of the art. Therefore, when personal data is transmitted, their use can be problematic, particularly in light of the requirements of Article 32 of the GDPR. WS-002 Outdated TLS versions
How can one check whether a server still supports TLS 1.0 or TLS 1.1?
For example, a test can be performed using the SSL Server Test from Qualys SSL Labs. Alternatively, the supported TLS version can also be tested via the command line. If a connection is established via TLS 1.1, the server will continue to accept this outdated protocol version.
How can the vulnerability be fixed?
TLS 1.0 and TLS 1.1 should be completely disabled on the server side and only TLS 1.2 and TLS 1.3 should be allowed. Additionally, the used cipher suites should be checked and the TLS configuration should be retested after any changes. WS-002 Outdated TLS versions
- 01 Technical background
- Our system WebScan analyzes your publicly accessible systems from the perspective of a potential attacker and automatically identifies external vulnerabilities.
- FAQ
- What is TLS and what is it used for?
- Why are TLS 1.0 and TLS 1.1 considered outdated?
- What risks arise from the use of outdated TLS versions?
- What is the data protection significance of outdated TLS versions?
- How can one check whether a server still supports TLS 1.0 or TLS 1.1?
- How can the vulnerability be fixed?
- FAQ




