Dell EMC Connectrix: Cisco MDS SSH False Positive Vulnerabilities

Summary: This article provides a list of security vulnerabilities that cannot be exploited on Dell EMC Connectrix Cisco MDS , but which may be identified by security scanners.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Security Article Type

Security KB

CVE Identifier

CVE-2001-0361, CVE-2001-0572, CVE-2001-1473, CVE-2008-5161

Issue Summary

CVE-2001-0361 - SSH Protocol Version 1 Session Key Retrieval
Description:
The remote SSH daemon supports connections made using the version 1.33 and/or 1.5 of the SSH protocol.
These protocols are not completely cryptographically safe so they should not be used.

CVE-2001-0572 - SSH Server CBC Mode Ciphers Enabled
Description:
The SSH server is configured to support Cipher Block Chaining (CBC) encryption. This may allow an attacker to recover the plaintext message from the ciphertext.
Note: This plugin only checks for the options of the SSH server and does not check for vulnerable software versions.

CVE-2001-1473 - SSH Weak MAC Algorithms Enabled
Description:
The remote SSH server is configured to allow either MD5 or 96-bit MAC algorithms, both of which are considered weak.
Note: This plugin only checks for the options of the SSH server, and it does not check for vulnerable software versions.

Recommendations

The vulnerabilities listed above are confirmed by Cisco Engineering that the Cisco MDS 9000 hardware and NX-OS software are not vulnerable.

Affected Products

Connectrix MDS-Series

Products

Connectrix MDS-Series Firmware
Article Properties
Article Number: 000196344
Article Type: Security KB
Last Modified: 29 Jun 2022
Version:  1
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.