GEN005511 - The SSH client must be configured to not use Cipher-Block Chaining (CBC)-based ciphers.

Information

The (CBC) mode of encryption as implemented in the SSHv2 protocol is vulnerable to chosen-plaintext attacks and must not be used.

Solution

Edit the SSH client configuration and remove any ciphers not starting with '3des' or 'aes' and remove any ciphers ending with 'cbc'. If necessary, add a 'Ciphers' line.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V1R14_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, CCI|CCI-000366, Rule-ID|SV-63595r1_rule, STIG-ID|GEN005511, Vuln-ID|V-22462

Plugin: Unix

Control ID: dec93f8072a417c6a17bbc36167a77f3fcea3e4d5b0c4399f4d9e33f0b1a3a96