Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.105611
Category:SSL and TLS
Title:Weak Encryption Algorithm(s) Supported (SSH)
Summary:The remote SSH server is configured to allow / support weak; encryption algorithm(s).
Description:Summary:
The remote SSH server is configured to allow / support weak
encryption algorithm(s).

Vulnerability Insight:
- The 'arcfour' cipher is the Arcfour stream cipher with 128-bit
keys. The Arcfour cipher is believed to be compatible with the RC4 cipher [SCHNEIER]. Arcfour
(and RC4) has problems with weak keys, and should not be used anymore.

- The 'none' algorithm specifies that no encryption is to be done. Note that this method provides
no confidentiality protection, and it is NOT RECOMMENDED to use it.

- A vulnerability exists in SSH messages that employ CBC mode that may allow an attacker to
recover plaintext from a block of ciphertext.

Solution:
Disable the reported weak encryption algorithm(s).

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:N/A:N

CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.