cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2832
Views
0
Helpful
2
Replies

Deprecated SSH Cryptographic Settings NEXUS 7000 Y 5000 NX-OS

Andresjair
Level 1
Level 1

Hello!

 

My customer recently run a vulnerability test on his Nexus 7000 and 5000 aquipment.

 

The test shows the following vulnerability  "Deprecated SSH Cryptographic Settings" within SSH configuration with the following impact "A man-in-the-middle attacker may be able to exploit this vulnerability to record the communication to decrypt the session key and even the messages" ."Type Name key exchange diffie-hellman-group1-sha1".


I couldn't find anything in the cisco documentation about how to remove this vulnerability.

 

Regarding the firmware version, no bug is found regarding this vulnerability.

Version NX-OS Release 7.3 (5) D1 (1)

 

Has anyone been able to fix this vulnerability ?

 

Thanks.

 

2 Replies 2

sagar123
Level 1
Level 1

how to remove this vulnerability.

This is an old thread. I would recommend you open a new one, and reference a CVE if you have one, or any relevant logs/info/details which could help identifying the problem/vulnerability.

 

Take care,

Sergiu

Review Cisco Networking for a $25 gift card