UCF STIG Viewer Logo

The SSH client must be configured to not use Cipher-Block Chaining (CBC) based ciphers.


Overview

Finding ID Version Rule ID IA Controls Severity
V-22462 GEN005511 SV-35193r1_rule ECSC-1 Medium
Description
The CBC mode of encryption as implemented in the SSHv2 protocol is vulnerable to chosen plaintext attacks and must not be used.
STIG Date
HP-UX 11.31 Security Technical Implementation Guide 2017-01-27

Details

Check Text ( None )
None
Fix Text (F-32008r1_fix)
Edit the configuration file and remove any ciphers other than those with the "aes" prefix and the "-ctr" suffix.