Avamar - 網路掃描器回報 Avamar 代理上的 OpenSSH 安全性漏洞
Summary: Avamar - 網路掃描器回報 Avamar 代理上的 OpenSSH 安全性漏洞。
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
網路安全掃描程式已識別 Avamar 代理 OpenSSH 服務的下列問題:
1.CVE-2016-2183 -「SSH 生日攻擊 64 位元封鎖密碼 (SWEET32)」
2.CVE-2016-10009、CVE-2016-10010、CVE-2016-10011、CVE-2016-10012、CVE-2016-8858 -「OpenSSH 7.4 中未安裝在系統上的多個漏洞」。
Cause
根據現有資訊,這些發現很可能是誤報。
1.代理上的 /etc/ssh/sshd_config 並未啟用任何 DES/3DES 加密。
2.Avamar 代理在 SUSE Linux Enterprise Server 12 SP5 (舊版代理版本為 SLES12 SP4) 上執行,並搭載 OpenSSH 7.2 版。
根據本知識文章「其他資訊」一節中的文件,這並非弱點。
1.代理上的 /etc/ssh/sshd_config 並未啟用任何 DES/3DES 加密。
2.Avamar 代理在 SUSE Linux Enterprise Server 12 SP5 (舊版代理版本為 SLES12 SP4) 上執行,並搭載 OpenSSH 7.2 版。
根據本知識文章「其他資訊」一節中的文件,這並非弱點。
Resolution
1.若要確認SWEET32問題不存在,可以嘗試使用 3DES 加密連接到代理。此命令可以在代理上本機執行,也可以遠端執行:
ssh -c 3des-cbc 193proxy.example.com
注意: 調整「193proxy.example.com」為代理主機名稱,如果在代理上執行命令,請使用 localhost 。
連線 應會失敗,然後 SSHD 服務會顯示允許的密碼。以下為輸出範例:
Unable to negotiate with ::1 port 22: no matching cipher found. Their offer: aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,aes192-cbc,aes256-cbc
2.若要確認 OpenSSH 套件版本高於 7.2p2-74.45.1 run this command:
rpm -qa | grep '^openssh-[7,f]' |sed 's/\.x86_64$//'
健全輸出:
admin@193proxy:~/>: rpm -qa | grep '^openssh-[7,f]' |sed 's/\.x86_64$//'
openssh-7.2p2-78.7.1
openssh-fips-7.2p2-78.7.1
Additional Information
關於此問題的 SUSE 說明文件:
1.Sweet32 - SUSE: CVE-2016-2183
2.版本 - SUSE: CVE-2016-10009、CVE-2016-10010、CVE-2016-10011、CVE-2016-10012、CVE-2016-8858
1.Sweet32 - SUSE: CVE-2016-2183
2.版本 - SUSE: CVE-2016-10009、CVE-2016-10010、CVE-2016-10011、CVE-2016-10012、CVE-2016-8858
Affected Products
AvamarArticle Properties
Article Number: 000209421
Article Type: Solution
Last Modified: 17 May 2023
Version: 2
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.