<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Vulnerability on our SMS in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Vulnerability-on-our-SMS/m-p/202988#M33784</link>
    <description>&lt;P&gt;We have scanned our SMS Server and found 2 vulnerablities. Can anyone suggest me how to fix them?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;1.&amp;nbsp;Weak Key Exchange (KEX) Algorithm(s) Supported (SSH)&lt;/P&gt;&lt;P&gt;The remote SSH server is configured to allow / support weak key exchange (KEX) algorithm(s).&lt;BR /&gt;Port 22/tcp&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;Weak Encryption Algorithm(s) Supported (SSH)&lt;/P&gt;&lt;P&gt;The remote SSH server is configured to allow / support weak encryption algorithm(s).&lt;BR /&gt;Port 22/tcp&lt;/P&gt;</description>
    <pubDate>Sat, 13 Jan 2024 07:56:03 GMT</pubDate>
    <dc:creator>gemechisd</dc:creator>
    <dc:date>2024-01-13T07:56:03Z</dc:date>
    <item>
      <title>Vulnerability on our SMS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulnerability-on-our-SMS/m-p/202988#M33784</link>
      <description>&lt;P&gt;We have scanned our SMS Server and found 2 vulnerablities. Can anyone suggest me how to fix them?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;1.&amp;nbsp;Weak Key Exchange (KEX) Algorithm(s) Supported (SSH)&lt;/P&gt;&lt;P&gt;The remote SSH server is configured to allow / support weak key exchange (KEX) algorithm(s).&lt;BR /&gt;Port 22/tcp&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;Weak Encryption Algorithm(s) Supported (SSH)&lt;/P&gt;&lt;P&gt;The remote SSH server is configured to allow / support weak encryption algorithm(s).&lt;BR /&gt;Port 22/tcp&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2024 07:56:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulnerability-on-our-SMS/m-p/202988#M33784</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2024-01-13T07:56:03Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability on our SMS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulnerability-on-our-SMS/m-p/202989#M33785</link>
      <description>&lt;P&gt;See the resources posted in reply to this discussion amongst others:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Management/How-to-disable-weak-ssh-cipher-on-R80-40-R81-10/td-p/189713#M35893" target="_blank"&gt;https://community.checkpoint.com/t5/Management/How-to-disable-weak-ssh-cipher-on-R80-40-R81-10/td-p/189713#M35893&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2024 08:11:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulnerability-on-our-SMS/m-p/202989#M33785</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-01-13T08:11:33Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability on our SMS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulnerability-on-our-SMS/m-p/202990#M33786</link>
      <description>&lt;P&gt;Which KEX and MAC were identified as weak by the scanner?&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2024 11:46:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulnerability-on-our-SMS/m-p/202990#M33786</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2024-01-13T11:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability on our SMS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulnerability-on-our-SMS/m-p/202992#M33787</link>
      <description>&lt;P&gt;I would say what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;gave is your solution. Btw, you can also run cipher_util from expert mode and see options available there.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2024 13:45:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulnerability-on-our-SMS/m-p/202992#M33787</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-13T13:45:37Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability on our SMS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulnerability-on-our-SMS/m-p/203088#M33793</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1702"&gt;@JozkoMrkvicka&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;For KEX&lt;BR /&gt;&lt;BR /&gt;- Disable the reported weak KEX algorithm(s)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;1024-bit MODP group / prime KEX algorithms:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Alternatively use elliptic-curve Diffie-Hellmann in general, e.g. Curve 25519.&lt;BR /&gt;&lt;BR /&gt;2. For MAC&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Disable the reported weak encryption algorithm(s).&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 12:00:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulnerability-on-our-SMS/m-p/203088#M33793</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2024-01-15T12:00:37Z</dc:date>
    </item>
  </channel>
</rss>

