cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1085
Views
0
Helpful
2
Replies

nexus 5.x software with openssh vulnerability

It seems that current nexus software version we have (5.1) still have openshh version 5.5 inside. There is a confirmed vulnerability in openssh which is resolved from version 5.7 onwards.

Does anybody know if nexus sw 5.2 has newer openssh version? Cannot find this in the release notes, or anywhere else. Any information on when Cisco will ramp up openssh version?

I know it is a tricky question, so any help is welcomed.

Bojan

2 Replies 2

ideasunlmtd
Level 1
Level 1

I have   cisco Nexus7000 and the current version 6.1 is having the openssh vulnerability and need to upgrade to

Upgrade to OpenSSH 5.7 or later .

please help !!!

Regards

Suresh

ashaw216
Level 1
Level 1

Nexus7000 running 6.2(2a), Qualys reports that it has the OpenSSH potential Denial of Service vulnerability in that is has an overly long LoginGraceTime and a lack of early connection release for MaxStartups settings  (QID 42413).  When will this be fixed?