Wednesday, September 9, 2015

SSH Protocol Version 1 Session Key Retrieval

Description:
The affected host support the use of SSH protocol version 1.33 and/or 1.5 which is associated to cryptography flaws.

Risk Level:
Medium

Implication:
An attacker could leverage this issue to decipher the encrypted data to obtain sensitive information.

Recommendation:
The affected host should be configured to disable the support SSH version 1

Manual verification:
command: ssh -1 ipaddr

No comments:

Post a Comment