07-16-2021 11:38 AM
Hi all, I'm not really sure if I should post this here or in Security (or both) but I have a Cisco Unified Communications Manager that is reporting a hit on Nessus Plugin ID 66848. This plugin indicates that the remote service (The CUCM) supports the use of null SSL ciphers. I am trying to find out what Common Vulnerability and Exposure (CVE) number this equates to and/or any patch/fix information that may be available.
Thanks for any help,
Respectfully,
Chuck Reel
07-16-2021 08:59 PM
If you don't configure the cipher string in the following fields:
All TLS or HTTPS TLS field—the HTTPS TLS interface port (8443) takes configuration from the Enterprise parameters (HTTPS ciphers) page.
All TLS or SIP TLS field—the SIP interface port (5061) takes configuration from the Enterprise parameters (TLS ciphers) page in encrypted mode and NULL-SHA ciphers in authenticated mode.
Go through the below guide,
07-18-2021 12:27 PM
Thank you Nithin, I am seeing this on Sunday afternoon, so I'm not at work, but I will certainly look into what you have said tomorrow morning
Respectfully,
Chuck Reel
08-04-2021 01:32 PM
So, I'm not sure I exactly followed what the intent of the response I received was other than to tell me to go through the CUCM Security Guide, but I thought I would provide an update to this thread for anyone who might find the information useful.
We have Secure and non Secure SIP trunks but that does not appear to have been the issue as none of these configurations were changed but the scan finding has been corrected.
Our secure SIP trunk profiles all use secure SIP profiles with TLS as the Inbound and Outgoing Transport Type and Device Security Mode set to Encrypted.
The issue appears to have been that we had several endpoints configured with non-secure device profiles. As soon as we changed all of our device profiles to a secure version the problem cleared.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide