Avamar - Netwerkscanner meldt beveiligingslek met OpenSSH op Avamar proxy
Summary: Avamar - Netwerkscanner meldt beveiligingslek met OpenSSH op Avamar proxy.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
Een netwerkbeveiligingsscanner heeft de volgende problemen vastgesteld met de Avamar proxy OpenSSH-service:
1.CVE-2016-2183 - "SSH Birthday attacks on 64-bit block ciphers (SWEET32)"
2.CVE-2016-10009, CVE-2016-10010, CVE-2016-10011, CVE-2016-10012, CVE-2016-8858 - "Multiple vulnerabilities in OpenSSH 7.4 which is not installed on the system."
Cause
Op basis van de beschikbare informatie is het waarschijnlijk dat deze bevindingen vals-positieven zijn.
1. De /etc/ssh/sshd_config op de proxy heeft GEEN DES/3DES-versleuteling ingeschakeld.
2. De Avamar proxy draait op SUSE Linux Enterprise Server 12 SP5 (of SLES12 SP4 in oudere proxyversies) en is uitgerust met OpenSSH versie 7.2.
Volgens de documentatie in het gedeelte 'Aanvullende informatie' van deze KB is dit niet kwetsbaar.
1. De /etc/ssh/sshd_config op de proxy heeft GEEN DES/3DES-versleuteling ingeschakeld.
2. De Avamar proxy draait op SUSE Linux Enterprise Server 12 SP5 (of SLES12 SP4 in oudere proxyversies) en is uitgerust met OpenSSH versie 7.2.
Volgens de documentatie in het gedeelte 'Aanvullende informatie' van deze KB is dit niet kwetsbaar.
Resolution
1. Om te controleren of het SWEET32-probleem niet aanwezig is, kunt u proberen verbinding te maken met de proxy met behulp van een 3DES-codering. Deze opdracht kan lokaal op de proxy of op afstand worden uitgevoerd:
ssh -c 3des-cbc 193proxy.example.com
OPMERKING: Pas aan dat "193proxy.example.com" de hostnaam van de proxy is of gebruik localhost als de opdracht op de proxy wordt uitgevoerd.
Als het goed is, mislukt de SSHD-service de toegestane cijfers. Hier is een voorbeeld van uitvoer:
Unable to negotiate with ::1 port 22: no matching cipher found. Their offer: aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,aes192-cbc,aes256-cbc
2. Om te bevestigen dat de OpenSSH-pakketversie hoger is dan 7.2p2-74.45.1 run this command:
rpm -qa | grep '^openssh-[7,f]' |sed 's/\.x86_64$//'
Gezonde output:
admin@193proxy:~/>: rpm -qa | grep '^openssh-[7,f]' |sed 's/\.x86_64$//'
openssh-7.2p2-78.7.1
openssh-fips-7.2p2-78.7.1
Additional Information
SUSE documentatie over dit probleem:
1. Sweet32 - SUSE: CVE-2016-2183
2. Version - SUSE: CVE-2016-10009, CVE-2016-10010, CVE-2016-10011, CVE-2016-10012, CVE-2016-8858
1. Sweet32 - SUSE: CVE-2016-2183
2. Version - SUSE: CVE-2016-10009, CVE-2016-10010, CVE-2016-10011, CVE-2016-10012, CVE-2016-8858
Affected Products
AvamarArticle Properties
Article Number: 000209421
Article Type: Solution
Last Modified: 17 May 2023
Version: 2
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.