GEN005511 M6 - The SSH client must be configured to not use CBC-based ciphers - 'CIPHERS does not include -CBC'

Information

The Cipher-Block Chaining (CBC) mode of encryption as implemented in the SSHv2 protocol is vulnerable to chosen plaintext attacks and must not be used.

Solution

Open a terminal session and edit the SSH client configuration file '/etc/ssh_config' and remove any ciphers ending with 'CBC'.

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, CCI|CCI-000366, Rule-ID|SV-39374r1_rule, STIG-ID|GEN005511-M6, Vuln-ID|V-22462

Plugin: Unix

Control ID: cf29bd105b50cd05696c036f3ebfc2ebd57c848dc45bec2db2875273bf4432d4