我們的品牌

Impact-Company-Logo-English Black-01-177x54

歡迎造訪施耐德電機全球網站

歡迎訪問我們的網站
		
我们今天能为您提供什么帮助?
APC Network Management Card 3 - CVE-2008-5161 - SSH CBC Detected

Issue:
A customer reports : "There is a Vulnerability on our NMC3's - CVE-2008-5161"

Product Line:
AP9640 / AP9641

Resolution:

This vulnerability involves cipher block chaining (CBC) on the SSH protocol which is considered  no longer safe as announced by Microsoft.

This issue is now fixed from v.3.1 onwards. This is also written on page 4 of the attached release notes from version 3.1.1.1 which is the latest version as of the publication of this article.

Shows the part of the table from 3111 Release notes Showing the Fix stating that SSH Cipher Block Chaining cipher has been removed

Aside from being a low-severity vulnerability (see CVSS v2.0 rating at https://nvd.nist.gov/vuln/detail/CVE-2008-5161), actions can be done to easily mitigate this, by following the security best practices such as:

  • Network segmentation
  • Using the NMC's Firewall to limit access to the device.
  • Putting the NMC behind a stateful firewall to limit access to the network where the NMC is installed.
  • Ensuring that all SSH clients are updated (do not use CBC ciphers).

By not defining which SSH cipher to use, the NMC3 always uses the strongest cipher available (aes256-ctr mac).

If you have any clarifications, please feel free to contact us at 1-800-800-4272 or chat with our technical support representatives.

    施耐德電機Taiwan

    探索更多
    產品:
    探索更多
    產品:

    需要協助?

    • 產品選型工具

      快速輕鬆地為您的應用找到合適的產品和附件。

    • 取得報價

      立即線上提交您的銷售需求,專業團隊將主動聯繫您。

    • 購買地點

      輕鬆在您所在地區找到最近的施耐德電機經銷商。

    • 支援中心

      在同一位置找到滿足您所有需求的支援資源。

    • 產品文檔
    • 軟體下載
    • 產品選型工具
    • 產品替代和替換
    • 幫助和聯絡中心
    • 尋找我們的辦公室
    • 取得報價
    • 人才招募
    • 公司簡介
    • 舉報不當行為
    • 無障礙
    • 新聞中心
    • 投資者
    • 專業洞察
    • 台灣施耐德電機學院
    • 綠色影響力落差調查
    • Schneider Go Green 2025
    • 隱私政策
    • Cookie通告
    • 使用條款
    • Change your cookie settings