11-23-2021 09:52 AM
Hi,
We have a WAP-150 access point, when we run a network scan it reports an issue with the SSL Cipher Sweet32 (port 4555). See below. Investigating further we can not find a way to disable this cipher.
Is it possible to change or disable this in the WAP-150?
Any help welcome...
Thanks in advance, Phil
SSL Medium Strength Cipher Suites Supported (SWEET32)
Description
The remote host supports the use of SSL ciphers that offer medium strength encryption. Nessus regards medium strength as any encryption that uses key lengths at least 64 bits and less than 112 bits, or else that uses the 3DES encryption suite.
Solved! Go to Solution.
11-23-2021 03:00 PM
The SWEET32 is an old vulnerability that pre-dates the WAP150 and is tracked in this PSIRT.
What you're seeing looks similar to BugID CSCvp26979 which was not resolved due to the End of Life status of the 500 Series. If you are already running the latest firmware for the WAP150 (1.1.3.2) and seeing this vulnerability, I would suggest opening a TAC case to determine if there is a similar bug opened for the WAP150 and/or a workaround/hotfix available.
11-23-2021 03:00 PM
The SWEET32 is an old vulnerability that pre-dates the WAP150 and is tracked in this PSIRT.
What you're seeing looks similar to BugID CSCvp26979 which was not resolved due to the End of Life status of the 500 Series. If you are already running the latest firmware for the WAP150 (1.1.3.2) and seeing this vulnerability, I would suggest opening a TAC case to determine if there is a similar bug opened for the WAP150 and/or a workaround/hotfix available.
12-06-2021 09:09 AM
Thanks for response.
Yes we are running the latest firmware that is a recent update, which would to me suggest it is still supported. A little frustrating if it is end of life as we have had this less than 1 year. We will try to figure out how to raise a TAC case..
Thanks,
Phil
12-06-2021 02:40 PM
To be clear, I did not say the WAP150 was end of life. I said "What you're seeing looks similar to BugID CSCvp26979 which was not resolved due to the End of Life status of the 500 Series."
The WAP150 is still available to purchase, so the End of Life has not yet been announced for that model.
You can open a support case via https://cisco.com/go/tac
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide