NetApp Console 连接器上的 SSH 弱密钥交换漏洞
适用于
- NetApp Console 连接器(代理)
- 打开 SSH
问题
由于启用了弱 SSH 密钥交换算法,安全工具在 Connector 上报告了漏洞 VULM-41063。
Connector 输出:
它显示启用了以下弱算法:
[root@cvo-connector-prod ~]# sshd -T | grep kexalgorithmsgssapikexalgorithms gss-group14-sha256-,gss-group16-sha512-,gss-nistp256-sha256-,gss-curve25519-sha256-,gss-group14-sha1-,gss-gex-sha1-kexalgorithms curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,diffie-hellman-group14-sha1[root@cvo-connector-prod ~]#[root@cvo-connector-prod ~]# sshd -T | grep gssapikexalgorithmsgssapikexalgorithms gss-group14-sha256-,gss-group16-sha512-,gss-nistp256-sha256-,gss-curve25519-sha256-,gss-group14-sha1-,gss-gex-sha1-[root@cvo-connector-prod ~]#它显示启用了以下弱算法:
gssapikexalgorithms:gss-group14-sha1-,gss-gex-sha1-
kexalgorithms:diffie-hellman-group14-sha1