07-13-2020 11:09 AM
Hello!
My customer recently run a vulnerability test on his Nexus 7000 and 5000 aquipment.
The test shows the following vulnerability "Deprecated SSH Cryptographic Settings" within SSH configuration with the following impact "A man-in-the-middle attacker may be able to exploit this vulnerability to record the communication to decrypt the session key and even the messages" ."Type Name key exchange diffie-hellman-group1-sha1".
I couldn't find anything in the cisco documentation about how to remove this vulnerability.
Regarding the firmware version, no bug is found regarding this vulnerability.
Version NX-OS Release 7.3 (5) D1 (1)
Has anyone been able to fix this vulnerability ?
Thanks.
10-26-2022 01:04 AM
how to remove this vulnerability.
10-28-2022 01:58 AM
This is an old thread. I would recommend you open a new one, and reference a CVE if you have one, or any relevant logs/info/details which could help identifying the problem/vulnerability.
Take care,
Sergiu
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide