|
|
|
|
|
|
|
| |
SSH Protocol Version 1 Session Key Retrieval |
|
| This script is Copyright (C) 2002-2010 Tenable Network Security, Inc. |
|
|
| Family | General |
| Nessus Plugin ID | 10882 (ssh1_proto_enabled.nasl) |
| Bugtraq ID | 2344
|
| CVE ID | CVE-2001-0361
|
|
| Description: |
Synopsis :
The remote service offers an insecure cryptographic protocol.
Description :
The remote SSH daemon supports connections made using the version 1.33
and/or 1.5 of the SSH protocol.
These protocols are not completely cryptographically safe so they
should not be used.
Solution :
Disable compatibility with version 1 of the protocol.
Risk factor :
Medium / CVSS Base Score : 4.0
(CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:N)
|
|
|
|
|
|