cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1677
Views
0
Helpful
4
Replies

Router vulnerability

amaresh_22jan
Level 1
Level 1

HI All,

 

We have router 3925  when scanned with one of tools below are few vulnerabilities we came across for the port 443. 

 

Kindly suggest to fix  the below  vulnerability.

 

SSL/TLS use of weak RC4 cipher-  port 443

 

SSLv3 Padding Oracle Attack Information Disclosure Vulnerability (POODLE) -443

 

SSL Server Has SSLv3 Enabled Vulnerability- 443

 

SSL/TLS Server supports TLSv1.0- Port 443

 

SSLv3.0/TLSv1.0 Protocol Weak CBC Mode Server Side Vulnerability (BEAST) – port 443

4 Replies 4

Leo Laohoo
Hall of Fame
Hall of Fame

All of this you've listed is CSCur23656.  The fix is to upgrade the IOS or disable SSLv3.  

SSL Padding Oracle On Downgraded Legacy Encryption (POODLE) Vulnerability

Thanks for the update.

 

Current IOS is Version 15.1(4)M3. So could you suggest us the IOS .

 

Another thing I wanted to know is if I disable 443 port on the router  thus it fix the some vulnerabilities.

 

 

 

 

 


@amaresh_22jan wrote:

Another thing I wanted to know is if I disable 443 port on the router  thus it fix the some vulnerabilities.

 


No it won't.  If SSLv3 is not used, then TURN IT OFF.

So best option is to Upgrade the IOS.

 

Could you provide me the config to disable the SSLv3 on the router