The Photon operating system must use an OpenSSH server version that does not support protocol 1.
DISA Rule
SV-256503r987796_rule
Vulnerability Number
V-256503
Group Title
SRG-OS-000074-GPOS-00042
Rule Version
PHTN-30-000026
Severity
CAT II
CCI(s)
- CCI-000197 - For password-based authentication, transmit passwords only cryptographically-protected channels.
- CCI-000803 - Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance for such authentication.
- CCI-000877 - Employ strong authentication in the establishment of nonlocal maintenance and diagnostic sessions.
- CCI-001941 - Implement replay-resistant authentication mechanisms for access to privileged accounts and/or non-privileged accounts.
- CCI-002420 - Maintain the confidentiality and/or integrity of information during preparation for transmission.
- CCI-002422 - Maintain the confidentiality and/or integrity of information during reception.
- CCI-002891 - Verify session and network connection termination after the completion of nonlocal maintenance and diagnostic sessions.
Weight
10
Fix Recommendation
Installing openssh manually is not supported by VMware for appliances. Revert to a previous backup or redeploy the appliance.
Check Contents
At the command line, run the following command:
# rpm -qa|grep openssh
If there is no output or openssh is not >= version 7.4, this is a finding.
Vulnerability Number
V-256503
Documentable
False
Rule Version
PHTN-30-000026
Severity Override Guidance
At the command line, run the following command:
# rpm -qa|grep openssh
If there is no output or openssh is not >= version 7.4, this is a finding.
Check Content Reference
M
Target Key
5520