跳转到主内容

OTV:ONTAP工具中的SSH漏洞

Views:
1
Visibility:
Public
Votes:
0
Category:
virtual-storage-console-for-vmware-vsphere<a>2010061158</a>
Specialty:
virt
Last Updated:

适用场景

  • 适用于VMware vSphere (OTV)的ONTAP工具9.12.
  • SSH (安全Shell)

问题描述

突出显示的SSH漏洞:

  1. 使用CFB或OFB的密码: 与新的密码链模式(如cr或gCM)相比、由于漏洞、这些密码被视为不常见且已弃用
  2. RC4密码 (ARCFFOUR, arcfour128, arcfour256): RC4密码不再被视为安全密码,并显示加密偏差
  3. 块大小为64位的加密算法 (DES、3DES、Blowfish、idea、cast): 这些加密算法可能容易受到生日攻击(Swedet32)
  4. 使用DH组1的密钥交换算法 (差分-赫尔曼-组1-SHA1、差分-赫尔曼-组14-SHA1、GSS-group1-SHA1-*): DH组1使用1024位密钥大小,这被认为太短,容易受到logjam模式攻击

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.