1003
Views
0
Helpful
0
Replies
SSH Server CBC Mode Ciphers & SSH Weak MAC Vulnerabilities Firesight
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-01-2017 01:22 PM - edited 03-10-2019 06:47 AM
I have a Firesight Management Server (2000) that manages various Firepower devices on my network. They are running the latest software versions.
My security auditor keeps flagging both the management server and the sensors for:
SSH Weak Algorithms enabled (MD5 & 96bit)
SSL 64bit block size ciphers (SWEET32 attack)
Is there any way to correct this through disabling certain ciphers, making modifications, etc.?
I do NOT want to lock myself out of my IPS system or damage the software.
thanks
Labels:
- Labels:
-
IPS and IDS
0 Replies 0
