Dell Unity: Nessus Full Safe Vulnerability Security Scan recommends disabling SSL/TLS CBC ciphers

Сводка: Nessus Full Safe Vulnerability Security Scan recommends disabling specific SSL/TLS CBC ciphers on Unity. Currently, these ciphers cannot be disabled on Unity.

Данная статья применяется к Данная статья не применяется к Эта статья не привязана к какому-либо конкретному продукту. В этой статье указаны не все версии продуктов.

Тип статьи по безопасности

Security KB

Сводка по проблеме

Nessus Full Safe Vulnerability Security Scan recommends disabling specific SSL/TLS CBC ciphers.

Supported CBC ciphers on Unity can also be detected through nmap script "ssl-enum-ciphers" over port 443.

Подробные сведения

After Unity with TLS 1.2 or higher is enabled, the Full Safe Vulnerability Security Scan may still report the following recommendations to remove CBC ciphers supported by Unity:

"The remote service supports the use of SSL Cipher Block Chaining ciphers, which combine previous blocks with subsequent ones"

"The remote host has open SSL/TLS ports which advertise discouraged cipher suites"

"The remote host supports the use of SSL ciphers that operate in Cipher Block Chaining (CBC) mode. These cipher suites offer additional security over Electronic Codebook (ECB) mode, but have the potential to leak information if used improperly"

CBC ciphers supported by Unity (OE 5.2.0.0.5.173) can also be detected using nmap script "ssl-enum-ciphers" over port 443:

TLS_DHE_RSA_WITH_AES_128_CBC_SHA 
TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 
TLS_DHE_RSA_WITH_AES_256_CBC_SHA 
TLS_DHE_RSA_WITH_AES_256_CBC_SHA256

Рекомендации

Currently, CBC ciphers cannot be disabled on Unity arrays and no workaround is available.

Затронутые продукты

Dell EMC Unity
Свойства статьи
Номер статьи: 000202982
Тип статьи: Security KB
Последнее изменение: 20 Jan 2026
Версия:  2
Получите ответы на свои вопросы от других пользователей Dell
Услуги технической поддержки
Проверьте, распространяются ли на ваше устройство услуги технической поддержки.