<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CSCuv19728 for the SSH issue. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-firewall-5500-issue/m-p/2798252#M173568</link>
    <description>&lt;P&gt;&lt;A title="blocked::https://tools.cisco.com/bugsearch/bug/CSCuv19728?emailclick=CNSemail" style="font-size: 10pt; font-family: Arial, Helvetica, sans-serif;" href="https://tools.cisco.com/bugsearch/bug/CSCuv19728?emailclick=CNSemail"&gt;&lt;SPAN title="blocked::https://tools.cisco.com/bugsearch/bug/CSCuv19728?emailclick=CNSemail" style="font-size: 10pt; font-family: Arial, Helvetica, sans-serif;"&gt;CSCuv19728&lt;/SPAN&gt;&lt;/A&gt; for the SSH issue.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 07 Feb 2016 18:03:28 GMT</pubDate>
    <dc:creator>ted.schwind</dc:creator>
    <dc:date>2016-02-07T18:03:28Z</dc:date>
    <item>
      <title>ASA firewall 5500 issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-5500-issue/m-p/2798249#M173565</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Trebuchet MS',sans-serif; color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Trebuchet MS',sans-serif; color: #1f497d;"&gt;We have received following penetration vulnerability for Cisco ASA Firewall 5500 (S/N: JM164940Q0)&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE width="883" style="width: 662.0pt; margin-left: -.65pt; border-collapse: collapse;"&gt;
&lt;TBODY&gt;
&lt;TR style="height: 30.75pt;"&gt;
&lt;TD width="468" style="width: 351.0pt; border: solid windowtext 1.0pt; background: #FFC000; padding: 0in 5.4pt 0in 5.4pt; height: 30.75pt;"&gt;
&lt;P style="text-align: center;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Trebuchet MS',sans-serif; color: black;"&gt;Vulnerabilities&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="137" style="width: 103.0pt; border: solid windowtext 1.0pt; border-left: none; background: #FFC000; padding: 0in 5.4pt 0in 5.4pt; height: 30.75pt;"&gt;
&lt;P style="text-align: center;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Trebuchet MS',sans-serif; color: black;"&gt;Risk/Severity&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="277" style="width: 208.0pt; border: solid windowtext 1.0pt; border-left: none; background: #FFC000; padding: 0in 5.4pt 0in 5.4pt; height: 30.75pt;"&gt;
&lt;P style="text-align: center;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Trebuchet MS',sans-serif; color: black;"&gt;Recommendation by vendor for closure of vulnerabilities&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 30.75pt;"&gt;
&lt;TD width="468" style="width: 351.0pt; border: solid windowtext 1.0pt; border-top: none; background: #FFC000; padding: 0in 5.4pt 0in 5.4pt; height: 30.75pt;"&gt;
&lt;P style="text-align: center;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Trebuchet MS',sans-serif; color: black;"&gt;Multiple issues related to SSL certificates were identified on hosts mentioned below:&lt;BR /&gt; &lt;BR /&gt; • SSL Version 3 Protocol Detection&lt;BR /&gt; • SSL Self-Signed Certificate&lt;BR /&gt; • SSL Weak Cipher Suites Supported&lt;BR /&gt; • Poodle attack is possible&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="137" style="width: 103.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; background: #FFC000; padding: 0in 5.4pt 0in 5.4pt; height: 30.75pt;"&gt;
&lt;P style="text-align: center;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Trebuchet MS',sans-serif; color: black;"&gt;Medium&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="277" style="width: 208.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; background: #FFC000; padding: 0in 5.4pt 0in 5.4pt; height: 30.75pt;"&gt;
&lt;P style="text-align: center;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Trebuchet MS',sans-serif; color: black;"&gt;It is recommended to implement these:-&lt;BR /&gt; &lt;BR /&gt; 1. Disable SSL 2.0/3.0 and use TLS 1.0, or higher instead.&lt;BR /&gt; 2. Purchase or generate a proper certificate for this service.&lt;BR /&gt; 3. Securely distribute and install the self-signed certificate to valid user's browser or if possible prefer to use a certificate signed by a trusted authority.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 30.75pt;"&gt;
&lt;TD width="468" style="width: 351.0pt; border: solid windowtext 1.0pt; border-top: none; background: #FFC000; padding: 0in 5.4pt 0in 5.4pt; height: 30.75pt;"&gt;
&lt;P style="text-align: center;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Trebuchet MS',sans-serif; color: black;"&gt;Multiple issues related to SSH were identified on hosts mentioned below:&lt;BR /&gt; &lt;BR /&gt; 1. SSH Server CBC Mode Ciphers Enabled&lt;BR /&gt; 2. SSH Protocal version 1.x is running on the reomte serverr&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="137" style="width: 103.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; background: #FFC000; padding: 0in 5.4pt 0in 5.4pt; height: 30.75pt;"&gt;
&lt;P style="text-align: center;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Trebuchet MS',sans-serif; color: black;"&gt;Medium&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="277" style="width: 208.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; background: #FFC000; padding: 0in 5.4pt 0in 5.4pt; height: 30.75pt;"&gt;
&lt;P style="text-align: center;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Trebuchet MS',sans-serif; color: black;"&gt;Contact the vendor or consult product documentation to disable CBC mode cipher encryption, and enable CTR or GCM cipher mode encryption&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:06:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-5500-issue/m-p/2798249#M173565</guid>
      <dc:creator>moreamol13</dc:creator>
      <dc:date>2019-03-12T07:06:45Z</dc:date>
    </item>
    <item>
      <title>plz tell me solution for this</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-5500-issue/m-p/2798250#M173566</link>
      <description>&lt;P&gt;plz tell me solution for this ,its very ungent&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2016 08:14:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-5500-issue/m-p/2798250#M173566</guid>
      <dc:creator>moreamol13</dc:creator>
      <dc:date>2016-01-06T08:14:00Z</dc:date>
    </item>
    <item>
      <title>You are running a legacy (non</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-5500-issue/m-p/2798251#M173567</link>
      <description>&lt;P&gt;You are running a legacy (non-X) ASA? Then you are quite limited what you can do.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Upgrade to the latest ASA-software.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://supportforums.cisco.com/document/12338141/guide-better-ssh-security"&gt;Disable SSHv2 and do some baseline-security&lt;/A&gt;. But there is nothing to disable CBC.&lt;/LI&gt;
&lt;LI&gt;For TLS: disable SSL and allow only strong ciphers:&lt;/LI&gt;
&lt;/OL&gt;
&lt;PRE class="prettyprint"&gt;ssl server-version tlsv1-only&lt;BR /&gt;ssl encryption dhe-aes128-sha1 dhe-aes256-sha1 aes128-sha1 aes256-sha1&lt;/PRE&gt;
&lt;P&gt;With a newer ASA (X-Models) there are some more options available.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;DIV class="field field-name-comment-body field-type-text-long field-label-hidden"&gt;
&lt;DIV class="field-items"&gt;
&lt;DIV class="field-item even" property="content:encoded"&gt;
&lt;P&gt;&amp;gt; plz tell me solution for this ,its very ungent&lt;/P&gt;
&lt;P&gt;This is a community-based forum where people help in their free time. If it's really urgent, you should open a TAC-case.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 06 Jan 2016 15:06:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-5500-issue/m-p/2798251#M173567</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-01-06T15:06:44Z</dc:date>
    </item>
    <item>
      <title>CSCuv19728 for the SSH issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-5500-issue/m-p/2798252#M173568</link>
      <description>&lt;P&gt;&lt;A title="blocked::https://tools.cisco.com/bugsearch/bug/CSCuv19728?emailclick=CNSemail" style="font-size: 10pt; font-family: Arial, Helvetica, sans-serif;" href="https://tools.cisco.com/bugsearch/bug/CSCuv19728?emailclick=CNSemail"&gt;&lt;SPAN title="blocked::https://tools.cisco.com/bugsearch/bug/CSCuv19728?emailclick=CNSemail" style="font-size: 10pt; font-family: Arial, Helvetica, sans-serif;"&gt;CSCuv19728&lt;/SPAN&gt;&lt;/A&gt; for the SSH issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Feb 2016 18:03:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-5500-issue/m-p/2798252#M173568</guid>
      <dc:creator>ted.schwind</dc:creator>
      <dc:date>2016-02-07T18:03:28Z</dc:date>
    </item>
  </channel>
</rss>

