Dell EMC Connectrix: Cisco MDS SSH False Positive Vulnerabilities
Summary: This article provides a list of security vulnerabilities that cannot be exploited on Dell EMC Connectrix Cisco MDS , but which may be identified by security scanners.
Security Article Type
Security KB
CVE Identifier
CVE-2001-0361, CVE-2001-0572, CVE-2001-1473, CVE-2008-5161
Issue Summary
CVE-2001-0361 - SSH Protocol Version 1 Session Key Retrieval
Description:
The remote SSH daemon supports connections made using the version 1.33 and/or 1.5 of the SSH protocol.
These protocols are not completely cryptographically safe so they should not be used.
CVE-2001-0572 - SSH Server CBC Mode Ciphers Enabled
Description:
The SSH server is configured to support Cipher Block Chaining (CBC) encryption. This may allow an attacker to recover the plaintext message from the ciphertext.
Note: This plugin only checks for the options of the SSH server and does not check for vulnerable software versions.
CVE-2001-1473 - SSH Weak MAC Algorithms Enabled
Description:
The remote SSH server is configured to allow either MD5 or 96-bit MAC algorithms, both of which are considered weak.
Note: This plugin only checks for the options of the SSH server, and it does not check for vulnerable software versions.