cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
939
Views
0
Helpful
1
Replies

vulnerabilities in CUCM

Vijay Patil
Level 3
Level 3

Our security team Run a NASSES  VUE Reports  in Network and  collected a   several Vulnerability & asking us for vulnerabilities about CUCM.

We are supporting CUCM 11.5 where below mentioned vulnerabilities are found

SSL Medium Strength Cipher Suites Supported
SSL Certificate Cannot Be Trusted
SSL Self-Signed Certificate
SSH Weak Algorithms Supported
SSH Server CBC Mode Ciphers Enabled

 

How we can resolve this..do we need to contact TAC...as there was no VUE ID  mentioned in the generated report

 

 

 

1 Reply 1

Jaime Valencia
Cisco Employee
Cisco Employee

You probably want them to provide you with more info on exactly what they're referring to. Or if they can provide you a reference to the security advisories and alerts from Cisco.

 

You can control the TLS version CUCM uses, some options regarding the ciphers used as well and you can definitely change the self-signed cert if they flag that as a vulnerability.

HTH

java

if this helps, please rate