27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>PVS</strong> ID: 1104 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:10863<br />

Description: Synopsis :\n\nThe remote SSL Server is configured to use weak encryption\n\nThe SSL<br />

server allows clients to connect using weak (export grade) Ciphers. As these ciphers are<br />

more easily cracked or hijacked, there is the potential of a remote session being taken over<br />

or observed. There is a risk of potential loss of confidential data.<br />

Solution: Disable weak ciphers on the TLS/SSL server.<br />

CVE Not available<br />

Weak SSL Ciphers Supported<br />

<strong>PVS</strong> ID: 1105 FAMILY: Web Servers RISK: LOW NESSUS ID:10863<br />

Description: Synopsis :\n\nThe remote SSL Server is configured to use weak encryption\n\nThe SSL<br />

server allows clients to connect using weak (export grade) Ciphers. As these ciphers are<br />

more easily cracked or hijacked, there is the potential of a remote session being taken over<br />

or observed. There is a risk of potential loss of confidential data.<br />

Solution: Disable weak ciphers on the TLS/SSL server.<br />

CVE Not available<br />

Internet Key Exchange (IKE) Server Detection<br />

<strong>PVS</strong> ID: 1106 FAMILY: Generic<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:11935<br />

Description: The remote host seems to be enabled to do Internet Key Exchange (IKE). This is typically<br />

indicative of a VPN server. VPN servers are used to connect remote hosts into internal<br />

resources. You should ensure that: the VPN is authorized for your Companies computing<br />

environment, the VPN utilizes strong encryption and that the VPN utilizes strong<br />

authentication.<br />

Solution: Contact your VPN vendor to ensure that you are operating at a security level commensurate<br />

with the assets being protected.<br />

CVE Not available<br />

Cisco IOS Version Detection<br />

<strong>PVS</strong> ID: 1107 FAMILY: Operating System Detection RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running Cisco IOS version %L<br />

Solution: N/A<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 282

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!