cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
423
Views
1
Helpful
1
Replies

OpenSSH Multiple Vulnerabilities - Cisco ISE Version 3.2.0.401

vtorres
Level 1
Level 1

I need to close an audit observation. My CISCO ISE platform has server version 3.2.0.542 path 3.5 and Cisco ISE version 3.2.0.401.

It has been detected that the OpenSSH version installed on the asset is older than 9.8. This version has two security holes described below: Vulnerability in sshd(8) which affects OpenSSH versions between 8.5p1 and 9.7p1. A race condition bug in sshd(8) could allow arbitrary code execution with root privileges. Logic bug in ssh(1) affects OpenSSH between versions 9.5 and 9.7.

Which version do you recommend upgrading?

1 Accepted Solution

Accepted Solutions

ammahend
VIP Alumni
VIP Alumni

Refer to the bug in the post, it has version with known fix, it was last modified on Dec 31 2024

https://community.cisco.com/t5/network-access-control/openssh-vulnerability-in-cisco-ise/td-p/5097878

-hope this helps-

View solution in original post

1 Reply 1

ammahend
VIP Alumni
VIP Alumni

Refer to the bug in the post, it has version with known fix, it was last modified on Dec 31 2024

https://community.cisco.com/t5/network-access-control/openssh-vulnerability-in-cisco-ise/td-p/5097878

-hope this helps-