<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change cipher in cisco devices in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/change-cipher-in-cisco-devices/m-p/4668587#M1092642</link>
    <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Fri, 12 Aug 2022 18:48:09 GMT</pubDate>
    <dc:creator>Leftz</dc:creator>
    <dc:date>2022-08-12T18:48:09Z</dc:date>
    <item>
      <title>Change cipher in cisco devices</title>
      <link>https://community.cisco.com/t5/network-security/change-cipher-in-cisco-devices/m-p/4667264#M1092557</link>
      <description>&lt;P&gt;Hi Please see the below. Command cannot be entered in C2900 switch. Is this switch not be supported or something else?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.PNG" style="width: 655px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/159686iA37DA0BC46FD540B/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.PNG" alt="2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A01(config)#do sh ip ssh&lt;BR /&gt;SSH Enabled - version 2.0&lt;BR /&gt;Authentication timeout: 120 secs; Authentication retries: 3&lt;BR /&gt;Minimum expected Diffie Hellman key size : 1024 bits&lt;BR /&gt;IOS Keys in SECSH format(ssh-rsa, base64 encoded):&lt;BR /&gt;ssh-rsa AAAAB3NzaC1yc2EAAAADndtyyuiugharwrtvvgbsyjyuiiuohjfghjr5BN0&lt;BR /&gt;b8Hvh9l+KJHw7GYPMGS9uCm2hdgjhdtydrutrynd5yxw==&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 14:37:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-cipher-in-cisco-devices/m-p/4667264#M1092557</guid>
      <dc:creator>Leftz</dc:creator>
      <dc:date>2022-08-10T14:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: Change cipher in cisco devices</title>
      <link>https://community.cisco.com/t5/network-security/change-cipher-in-cisco-devices/m-p/4667279#M1092562</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1190993"&gt;@Leftz&lt;/a&gt; this guide implies thats SSH ciphers is not configurable &lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2960/software/release/12-2_40_se/configuration/guide/scg.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2960/software/release/12-2_40_se/configuration/guide/scg.pdf&lt;/A&gt; those commands would certainly work on newer IOS-XE images.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 14:51:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-cipher-in-cisco-devices/m-p/4667279#M1092562</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-08-10T14:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Change cipher in cisco devices</title>
      <link>https://community.cisco.com/t5/network-security/change-cipher-in-cisco-devices/m-p/4667327#M1092567</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Thank you for your reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the below info. Is it possible to remediate the issue without upgrading ios? thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Deprecated SSH Cryptographic Settings port 22/tcp&lt;BR /&gt;QID:&lt;BR /&gt;38739&lt;BR /&gt;Category:&lt;BR /&gt;General remote services&lt;BR /&gt;Associated CVEs:&lt;BR /&gt;-&lt;BR /&gt;Vendor Reference&lt;BR /&gt;-&lt;BR /&gt;Bugtraq ID:&lt;BR /&gt;-&lt;BR /&gt;Service Modified:&lt;BR /&gt;05/26/2021&lt;BR /&gt;User Modified:&lt;BR /&gt;-&lt;BR /&gt;Edited:&lt;BR /&gt;No&lt;BR /&gt;PCI Vuln:&lt;BR /&gt;Yes&lt;BR /&gt;THREAT:&lt;BR /&gt;The SSH protocol (Secure Shell) is a method for secure remote login from one computer to another.&lt;BR /&gt;The target is using deprecated SSH cryptographic settings to communicate.&lt;/P&gt;&lt;P&gt;IMPACT:&lt;BR /&gt;A man-in-the-middle attacker may be able to exploit this vulnerability to record the communication to decrypt the session key and even the messages.&lt;BR /&gt;SOLUTION:&lt;BR /&gt;Avoid using deprecated cryptographic settings.&lt;BR /&gt;Use best practices when configuring SSH.&lt;/P&gt;&lt;P&gt;Refer to Security of Interactive and Automated Access Management Using Secure Shell (SSH) .&lt;/P&gt;&lt;P&gt;Settings currently considered deprecated:&lt;/P&gt;&lt;P&gt;Ciphers using CFB of OFB&lt;BR /&gt;Very uncommon, and deprecated because of weaknesses compared to newer cipher chaining modes such as CTR or GCM&lt;BR /&gt;RC4 cipher (arcfour, arcfour128, arcfour256)&lt;BR /&gt;The RC4 cipher has a cryptographic bias and is no longer considered secure&lt;BR /&gt;Ciphers with a 64-bit block size (DES, 3DES, Blowfish, IDEA, CAST)&lt;BR /&gt;Ciphers with a 64-bit block size may be vulnerable to birthday attacks (Sweet32)&lt;BR /&gt;Key exchange algorithms using DH group 1 (diffie-hellman-group1-sha1, gss-group1-sha1-*)&lt;BR /&gt;DH group 1 uses a 1024-bit key which is considered too short and vulnerable to Logjam-style attacks&lt;BR /&gt;Key exchange algorithm "rsa1024sha1"&lt;BR /&gt;Very uncommon, and deprecated because of the short RSA key size&lt;BR /&gt;MAC algorithm "umac-32"&lt;BR /&gt;Very uncommon, and deprecated because of the very short MAC length&lt;BR /&gt;Cipher "none"&lt;BR /&gt;This is available only in SSHv1&lt;BR /&gt;COMPLIANCE:&lt;BR /&gt;Not Applicable&lt;BR /&gt;EXPLOITABILITY:&lt;BR /&gt;There is no exploitability information for this vulnerability.&lt;BR /&gt;ASSOCIATED MALWARE:&lt;BR /&gt;There is no malware information for this vulnerability.&lt;BR /&gt;RESULTS:&lt;BR /&gt;Type Name&lt;BR /&gt;key exchange diffie-hellman-group1-sha1&lt;BR /&gt;cipher 3des-cbc&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 16:19:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-cipher-in-cisco-devices/m-p/4667327#M1092567</guid>
      <dc:creator>Leftz</dc:creator>
      <dc:date>2022-08-10T16:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: Change cipher in cisco devices</title>
      <link>https://community.cisco.com/t5/network-security/change-cipher-in-cisco-devices/m-p/4667329#M1092568</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1190993"&gt;@Leftz&lt;/a&gt; apply a VTY line ACL that limits SSH access to the switch to trusted networks (IT VLANs or dedicated Jump servers etc) will reduce the attack surface. Ideally you'd replace the hardware with something newer that supports stronger ciphers. &lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 16:26:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-cipher-in-cisco-devices/m-p/4667329#M1092568</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-08-10T16:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: Change cipher in cisco devices</title>
      <link>https://community.cisco.com/t5/network-security/change-cipher-in-cisco-devices/m-p/4667446#M1092580</link>
      <description>&lt;P&gt;....&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 19:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-cipher-in-cisco-devices/m-p/4667446#M1092580</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-08-12T19:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: Change cipher in cisco devices</title>
      <link>https://community.cisco.com/t5/network-security/change-cipher-in-cisco-devices/m-p/4668587#M1092642</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 18:48:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-cipher-in-cisco-devices/m-p/4668587#M1092642</guid>
      <dc:creator>Leftz</dc:creator>
      <dc:date>2022-08-12T18:48:09Z</dc:date>
    </item>
  </channel>
</rss>

