One-third of all HTTPS websites open to DROWN attack

The vulnerability scanner is trying to perform an SSLv2 handshake, so that fact that it was able to means that something on that server is vulnerable.

Suspect it doesn't have to be "that server" but could include the load balancer et al used to front your site. Any one know if F5's Big-IP is vulnerable to DROWN?

