Avamar - 网络扫描仪报告 Avamar 代理上的 OpenSSH 安全漏洞
Summary: Avamar - 网络扫描仪报告 Avamar 代理上的 OpenSSH 安全漏洞。
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
网络安全扫描程序已识别 Avamar 代理 OpenSSH 服务的以下问题:
1.CVE-2016-2183 - “SSH Birthday attacks on 64-bit block ciphers (SWEET32)”
2.CVE-2016-10009, CVE-2016-10010, CVE-2016-10011, CVE-2016-10012, CVE-2016-8858 - “Multiple vulnerabilities in OpenSSH 7.4 which is not installed on the system.”
Cause
根据现有信息,这些发现很可能是误报。
1.代理上的 /etc/ssh/sshd_config 未启用任何 DES/3DES 密码。
2.Avamar 代理在 SUSE Linux Enterprise Server 12 SP5(或较旧代理版本中的 SLES12 SP4)上运行,并配备了 OpenSSH 7.2 版。
根据本知识库文章的“其他信息”部分中提供的文档,这不易受影响。
1.代理上的 /etc/ssh/sshd_config 未启用任何 DES/3DES 密码。
2.Avamar 代理在 SUSE Linux Enterprise Server 12 SP5(或较旧代理版本中的 SLES12 SP4)上运行,并配备了 OpenSSH 7.2 版。
根据本知识库文章的“其他信息”部分中提供的文档,这不易受影响。
Resolution
1.要确认不存在SWEET32问题,您可以尝试使用 3DES 密码连接到代理。此命令可以在代理上本地运行,也可以远程运行:
ssh -c 3des-cbc 193proxy.example.com
提醒: 调整为“193proxy.example.com”作为代理主机名,或者如果在代理上运行命令,则使用 localhost 。
连接 应失败,然后 SSHD 服务将显示允许的密码。下面是一个示例输出:
Unable to negotiate with ::1 port 22: no matching cipher found. Their offer: aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,aes192-cbc,aes256-cbc
2.确认 OpenSSH 软件包版本高于 7.2p2-74.45.1 run this command:
rpm -qa | grep '^openssh-[7,f]' |sed 's/\.x86_64$//'
正常输出:
admin@193proxy:~/>: rpm -qa | grep '^openssh-[7,f]' |sed 's/\.x86_64$//'
openssh-7.2p2-78.7.1
openssh-fips-7.2p2-78.7.1
Additional Information
关于此问题的 SUSE 文档:
1.Sweet32 - SUSE: CVE-2016-2183
2.版本 — SUSE: CVE-2016-10009、CVE-2016-10010、CVE-2016-10011、CVE-2016-10012、CVE-2016-8858
1.Sweet32 - SUSE: CVE-2016-2183
2.版本 — SUSE: CVE-2016-10009、CVE-2016-10010、CVE-2016-10011、CVE-2016-10012、CVE-2016-8858
Affected Products
AvamarArticle Properties
Article Number: 000209421
Article Type: Solution
Last Modified: 17 May 2023
Version: 2
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.