12-08-2015 09:15 AM - edited 03-08-2019 03:01 AM
Hi All,
We are running Nexus 7000's - v6.2(10) - and a Nessus scan is reporting this vulnerability:
OpenSSH MaxAuthTries Limit Bypass Vulnerability
The solution says to upgrade to OpenSSH 7.0 or later.
Do you know how I would do this? Is an OS upgrade required or is there anything else I can do?
Many thanks in advance.
Kind regards
Alex
Solved! Go to Solution.
12-08-2015 01:58 PM
Hi Alex,
You would need to install new NX-OS software.
Incidentally if you need to check the current version of openSSH just telnet to port 22 .
With the ASA, Cisco publish opensource licence info:
http://www.cisco.com/c/en/us/support/security/asa-5500-series-next-generation-firewalls/products-licensing-information-listing.html
...sadly with the Nexus, this information is lacking and not very up to date:
http://www.cisco.com/c/en/us/support/switches/nexus-7000-series-switches/products-licensing-information-listing.html
cheers,
Seb.
12-08-2015 01:58 PM
Hi Alex,
You would need to install new NX-OS software.
Incidentally if you need to check the current version of openSSH just telnet to port 22 .
With the ASA, Cisco publish opensource licence info:
http://www.cisco.com/c/en/us/support/security/asa-5500-series-next-generation-firewalls/products-licensing-information-listing.html
...sadly with the Nexus, this information is lacking and not very up to date:
http://www.cisco.com/c/en/us/support/switches/nexus-7000-series-switches/products-licensing-information-listing.html
cheers,
Seb.
12-09-2015 01:28 AM
Hi Seb,
Thank you so much for your quick response, it really is appreciated.
Thanks also for the tip to find out the openSSH version. I've been looking for a good way to fund that out for a while.
Kind regards
Alex
02-07-2016 01:33 AM
Hi All,
I have the same problem on nexus 9504 running latest 7.0(3)I1(3) and security scan showing the same vulnerability: openssh maxauthtries bypass.
I can see no license information available for 7.0(3)I1(3).
How to fix this vulnerability?
Best Regards,
Mohammad Taamneh
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide