09-18-2012 03:58 AM - edited 03-07-2019 08:56 AM
It seems that current nexus software version we have (5.1) still have openshh version 5.5 inside. There is a confirmed vulnerability in openssh which is resolved from version 5.7 onwards.
Does anybody know if nexus sw 5.2 has newer openssh version? Cannot find this in the release notes, or anywhere else. Any information on when Cisco will ramp up openssh version?
I know it is a tricky question, so any help is welcomed.
Bojan
05-17-2013 02:34 AM
I have cisco Nexus7000 and the current version 6.1 is having the openssh vulnerability and need to upgrade to
Upgrade to OpenSSH 5.7 or later .
please help !!!
Regards
Suresh
11-26-2013 06:56 AM
Nexus7000 running 6.2(2a), Qualys reports that it has the OpenSSH potential Denial of Service vulnerability in that is has an overly long LoginGraceTime and a lack of early connection release for MaxStartups settings (QID 42413). When will this be fixed?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide