11-22-2017 11:50 PM - edited 03-20-2019 09:43 PM
HI All,
We have router 3925 when scanned with one of tools below are few vulnerabilities we came across for the port 443.
Kindly suggest to fix the below vulnerability.
SSL/TLS use of weak RC4 cipher- port 443
SSLv3 Padding Oracle Attack Information Disclosure Vulnerability (POODLE) -443
SSL Server Has SSLv3 Enabled Vulnerability- 443
SSL/TLS Server supports TLSv1.0- Port 443
SSLv3.0/TLSv1.0 Protocol Weak CBC Mode Server Side Vulnerability (BEAST) – port 443
11-22-2017 11:54 PM - edited 11-22-2017 11:57 PM
All of this you've listed is CSCur23656. The fix is to upgrade the IOS or disable SSLv3.
SSL Padding Oracle On Downgraded Legacy Encryption (POODLE) Vulnerability
11-23-2017 01:18 AM
Thanks for the update.
Current IOS is Version 15.1(4)M3. So could you suggest us the IOS .
Another thing I wanted to know is if I disable 443 port on the router thus it fix the some vulnerabilities.
11-23-2017 02:04 AM
@amaresh_22jan wrote:
Another thing I wanted to know is if I disable 443 port on the router thus it fix the some vulnerabilities.
No it won't. If SSLv3 is not used, then TURN IT OFF.
11-23-2017 03:33 AM
So best option is to Upgrade the IOS.
Could you provide me the config to disable the SSLv3 on the router
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide