This usually means that the gateway is still allowing the legacy 3DES cipher suite TLS_RSA_WITH_3DES_EDE_CBC_SHA under TLS 1.2.
I would first check the gateway's TLS/cipher-suite configuration and disable 3DES if the software allows it. After making the change, restart the relevant service and run the security scan again to confirm that the cipher is no longer accepted.
Since you're running Gateway version 5.14.00.12, it would also be worth checking the vendor's documentation or release notes to see whether there is a configuration setting or update specifically addressing SWEET32/3DES.
MichaR489
1 Rookie
•
12 Posts
1
0
Posted October 23rd, 2023 12:53
After updating to 5.18.00.20 the vulnerability is present again ;(
many greetings
Michael