GEN005500 - The SSH daemon must be configured to only use the SSHv2 protocol

Information

SSHv1 is not a DoD-approved protocol and has many well-known vulnerability exploits. Exploits of the SSH daemon could provide immediate root access to the system.

Solution

Edit the configuration file and modify the Protocol line entry to appear as follows:

Protocol 2

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|I, CCI|CCI-001436, CSCv6|9.1, Rule-ID|SV-35209r1_rule, STIG-ID|GEN005500, Vuln-ID|V-4295

Plugin: Unix

Control ID: 3b0fa232a335d50d1a44a6f43174adb0860fc305b5a4f1da7779cf2b3e13f61f