<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH Server CBC Mode Ciphers Enabled in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ssh-server-cbc-mode-ciphers-enabled/m-p/4503893#M235662</link>
    <description>&lt;P&gt;You should reach out to TAC and see if there is a command you can run.&amp;nbsp; I know there is a command on the controllers to disable weak ciphers, but don't know if that is available for ap's.&amp;nbsp; It's probably best to just disable ssh and only enable it if and when you need it.&amp;nbsp; You can always run a debug ap command, then you don't have to ssh.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;debug ap &amp;lt;ap name&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;debug ap command "&amp;lt;your command&amp;gt;" &amp;lt;ap name&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Nov 2021 02:32:28 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2021-11-17T02:32:28Z</dc:date>
    <item>
      <title>SSH Server CBC Mode Ciphers Enabled</title>
      <link>https://community.cisco.com/t5/wireless/ssh-server-cbc-mode-ciphers-enabled/m-p/4503629#M235650</link>
      <description>&lt;P&gt;After a pentest I got this low vulnerability on some access points:&lt;/P&gt;&lt;P&gt;CVE-2008-5161&lt;/P&gt;&lt;P&gt;Description: The SSH server is configured to support Cipher Block Chaining (CBC)&lt;BR /&gt;encryption.&amp;nbsp; This may allow an attacker to recover the plaintext message&lt;BR /&gt;from the ciphertext.&lt;BR /&gt;&lt;BR /&gt;Note that this plugin only checks for the options of the SSH server and&lt;BR /&gt;does not check for vulnerable software versions.&lt;/P&gt;&lt;P&gt;Solution: Contact the vendor or consult product documentation to disable CBC mode&lt;BR /&gt;cipher encryption, and enable CTR or GCM cipher mode encryption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to remediate this? or the workaround is just disable SSH on APs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 15:44:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssh-server-cbc-mode-ciphers-enabled/m-p/4503629#M235650</guid>
      <dc:creator>JohanGonzalez4730</dc:creator>
      <dc:date>2021-11-16T15:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Server CBC Mode Ciphers Enabled</title>
      <link>https://community.cisco.com/t5/wireless/ssh-server-cbc-mode-ciphers-enabled/m-p/4503701#M235651</link>
      <description>&lt;P&gt;WLC 2504 version 8.5.171.0&lt;/P&gt;&lt;P&gt;APs 3802I&lt;/P&gt;&lt;P&gt;The vulnerability was only found on the AP side.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 17:22:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssh-server-cbc-mode-ciphers-enabled/m-p/4503701#M235651</guid>
      <dc:creator>JohanGonzalez4730</dc:creator>
      <dc:date>2021-11-16T17:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Server CBC Mode Ciphers Enabled</title>
      <link>https://community.cisco.com/t5/wireless/ssh-server-cbc-mode-ciphers-enabled/m-p/4503893#M235662</link>
      <description>&lt;P&gt;You should reach out to TAC and see if there is a command you can run.&amp;nbsp; I know there is a command on the controllers to disable weak ciphers, but don't know if that is available for ap's.&amp;nbsp; It's probably best to just disable ssh and only enable it if and when you need it.&amp;nbsp; You can always run a debug ap command, then you don't have to ssh.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;debug ap &amp;lt;ap name&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;debug ap command "&amp;lt;your command&amp;gt;" &amp;lt;ap name&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 02:32:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssh-server-cbc-mode-ciphers-enabled/m-p/4503893#M235662</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2021-11-17T02:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Server CBC Mode Ciphers Enabled</title>
      <link>https://community.cisco.com/t5/wireless/ssh-server-cbc-mode-ciphers-enabled/m-p/4701621#M247006</link>
      <description>&lt;P&gt;Hi Scott,&lt;/P&gt;
&lt;P&gt;Good day to you. You mentioned "&lt;SPAN&gt;I know there is a command on the controllers to disable weak ciphers",&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can you share the command please? &lt;BR /&gt;I faced this same issue but on WLC, been searching for a while now.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Appreciate your help.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 03:54:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssh-server-cbc-mode-ciphers-enabled/m-p/4701621#M247006</guid>
      <dc:creator>izi</dc:creator>
      <dc:date>2022-10-12T03:54:28Z</dc:date>
    </item>
  </channel>
</rss>

