GEN005501 - The SSH client must be configured to only use the SSHv2 protocol

Information

SSHv1 is not a DoD-approved protocol and has many well-known vulnerability exploits. Exploits of the SSH client could provide access to the system with the privileges of the user running the client.

Solution

Edit the client configuration file Protocol entry to look like:

Protocol 2

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-001436, CSCv6|9.1, Rule-ID|SV-35212r1_rule, STIG-ID|GEN005501, Vuln-ID|V-22456

Plugin: Unix

Control ID: fddc4a46da2b41861aa2e4babd5221f269952e0e394b889ec332e536ea9c1acb