NET1647 - The network element must not allow SSH Version 1

Information

The network element must not use SSH Version 1 for administrative access.

SSH Version 1 is a protocol that has never been defined in a standard. Since SSH-1 has inherent design flaws which make it vulnerable to, e.g., man-in-the-middle attacks, it is now generally considered obsolete and should be avoided by explicitly disabling fallback to SSH-1.

Solution

Configure the network element to use SSH version 2.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R29_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, Rule-ID|SV-15460r2_rule, STIG-ID|NET1647, Vuln-ID|V-14717

Plugin: Cisco

Control ID: b74fbd3fdfd9f3e19e0540d6adbac857ee76f6ef59431ee5bd9429fe0442f8d8