<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco 5508 Controllers vulnerabilities in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/cisco-5508-controllers-vulnerabilities/m-p/3858961#M26660</link>
    <description>&lt;P&gt;&amp;nbsp;are there any extra commands needed to be done after the upgrade ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your concern Haydn&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 19 May 2019 14:29:43 GMT</pubDate>
    <dc:creator>Amr_Elsherif</dc:creator>
    <dc:date>2019-05-19T14:29:43Z</dc:date>
    <item>
      <title>Cisco 5508 Controllers vulnerabilities</title>
      <link>https://community.cisco.com/t5/wireless/cisco-5508-controllers-vulnerabilities/m-p/3858779#M26657</link>
      <description>&lt;P&gt;wlc 5508 running version&amp;nbsp;&amp;nbsp;8.2.170.0 shows the below vulnerabilities, how can these be mitigated?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SSL Certificate Signed Using Weak Hashing Algorithm&lt;BR /&gt;SSH Weak Algorithms Supported&lt;BR /&gt;SSH Server CBC Mode Ciphers Enabled&lt;BR /&gt;SSH Weak MAC Algorithms Enabled&lt;BR /&gt;SSL Certificate Chain Contains RSA Keys Less Than 2048 bits&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 17:25:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-5508-controllers-vulnerabilities/m-p/3858779#M26657</guid>
      <dc:creator>Amr_Elsherif</dc:creator>
      <dc:date>2021-07-05T17:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5508 Controllers vulnerabilities</title>
      <link>https://community.cisco.com/t5/wireless/cisco-5508-controllers-vulnerabilities/m-p/3858788#M26658</link>
      <description>&lt;P&gt;How to mitigate them would be an upgrade.&lt;/P&gt;&lt;P&gt;The version to upgrade to would have been advised in the security advisory notice that the vulnerability was announced in or the release notes for the version you are upgrading to.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As most of these are SSL and SSH vulnerabilities also recommend ACL/ FW rules to only allow these protocols from known sources.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When considering an upgrade here are two good links to review:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/compatibility/matrix/compatibility-matrix.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/compatibility/matrix/compatibility-matrix.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 18 May 2019 16:26:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-5508-controllers-vulnerabilities/m-p/3858788#M26658</guid>
      <dc:creator>Haydn Andrews</dc:creator>
      <dc:date>2019-05-18T16:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5508 Controllers vulnerabilities</title>
      <link>https://community.cisco.com/t5/wireless/cisco-5508-controllers-vulnerabilities/m-p/3858960#M26659</link>
      <description>&lt;P&gt;&amp;nbsp;are there any extra commands needed to be done after the upgrade ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your concern Haydn&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 May 2019 14:29:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-5508-controllers-vulnerabilities/m-p/3858960#M26659</guid>
      <dc:creator>Amr_Elsherif</dc:creator>
      <dc:date>2019-05-19T14:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5508 Controllers vulnerabilities</title>
      <link>https://community.cisco.com/t5/wireless/cisco-5508-controllers-vulnerabilities/m-p/3858961#M26660</link>
      <description>&lt;P&gt;&amp;nbsp;are there any extra commands needed to be done after the upgrade ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your concern Haydn&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 May 2019 14:29:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-5508-controllers-vulnerabilities/m-p/3858961#M26660</guid>
      <dc:creator>Amr_Elsherif</dc:creator>
      <dc:date>2019-05-19T14:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5508 Controllers vulnerabilities</title>
      <link>https://community.cisco.com/t5/wireless/cisco-5508-controllers-vulnerabilities/m-p/3859059#M26661</link>
      <description>&lt;P&gt;You can run one of the following commands should you want to verify security strength after the upgrade:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;(Cisco Controller) &amp;gt;show certificate? &lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;all Display all installed certificate details&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;compatibility Enable compatibility mode for inter-switch ipsec&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;eap Display EAP cert. details&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;ipsec Display IPSec cert. details&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;lsc Display Locally Significant Certificate (LSC)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;ssc Display Self Signed Device Certificate (SSC)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;summary Display SSL certificates&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;webadmin Display Web Administration cert. details&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;webauth Display Web Authentication cert. details&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;lt;&amp;lt;&amp;lt; Please help the community by marking useful posts helpful, or accept as a solution if it resolved your issue &amp;gt;&amp;gt;&amp;gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 00:41:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-5508-controllers-vulnerabilities/m-p/3859059#M26661</guid>
      <dc:creator>Jurgens L</dc:creator>
      <dc:date>2019-05-20T00:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5508 Controllers vulnerabilities</title>
      <link>https://community.cisco.com/t5/wireless/cisco-5508-controllers-vulnerabilities/m-p/3859201#M26662</link>
      <description>The option you want is named "Cipher-Option High", which would mitigate most of those points. Not sure which software release has added it though. &lt;BR /&gt;For compatibility reasons some old variants will also stay enabled! So not all points will disappear in a scan.</description>
      <pubDate>Mon, 20 May 2019 08:42:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-5508-controllers-vulnerabilities/m-p/3859201#M26662</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-05-20T08:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 5508 Controllers vulnerabilities</title>
      <link>https://community.cisco.com/t5/wireless/cisco-5508-controllers-vulnerabilities/m-p/3859713#M26663</link>
      <description>Upgrade the firmware of the controller.</description>
      <pubDate>Mon, 20 May 2019 21:21:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-5508-controllers-vulnerabilities/m-p/3859713#M26663</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2019-05-20T21:21:19Z</dc:date>
    </item>
  </channel>
</rss>

