Mitigation recommendation for certain vulnerability assesment done by VAPT team

cancel
Showing results for 
Search instead for 
Did you mean: 

Mitigation recommendation for certain vulnerability assesment done by VAPT team

L1 Bithead

Hi Team,

 

Current PAN OS -8.1.10

Customer had run a VAPT assesment where they came up with certain Vulnerability such as

90317 - SSH Weak Algorithms Supported

70658 - SSH Server CBC Mode Ciphers Enabled

71049 - SSH Weak MAC Algorithms Enabled

While checking certain things are not there from the firewall end but while checking using their Vulnerability Assessment tool they are having these mentioned output as above mentioned vulnerability.

Below is the firewall Output

 

Firewall output:

# show deviceconfig system ssh ciphers mgmt
aes128-ctr;
aes128-gcm;
aes192-ctr;
aes256-ctr;
aes256-gcm;

 

# show deviceconfig system ssh mac mgmt
 {
hmac-sha2-256;
hmac-sha2-512;

}

 

Are the above mentioned Vulnerability is addressed in any other PAN OS version?

 

2 REPLIES 2

L0 Member

Step 1: Conduct Risk Identification And Analysis.

Step 2: Vulnerability Scanning Policies and Procedures.

Step 3: Identify The Types Of Vulnerability mylonestar Scans.

Step 4: Configure The Scan.

Step 5: Perform The Scan.

Step 6: Evaluate And Consider Possible Risks.

Step 7: Interpret The Scan Results.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!