This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSH version and vulnerability

Hi there.

I just noticed a new Vulnerability here: https://www.exploit-db.com/exploits/40888/

as it states any ssh below 7.3 is affected.  this includes Sophos UTM 9.4

sophos_utm:/ # ssh -v localhost
OpenSSH_6.2p2, OpenSSL 1.0.1k 8 Jan 2015

 Any sign that Sophos is going to update this outdated SSH and SSL?

 



This thread was automatically locked due to age.
Parents
  • I'd imagine it would eventually be patched/upgraded. However, SSH shouldn't be open on the internet and you should close yours if it is. So this vulnerability should only be an issue if you have someone on your network trying to hack port 22 of your UTM

  • Further you change your default ssh port and only change it to standard if your ssh software can't work with a none standard port.

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Further you change your default ssh port and only change it to standard if your ssh software can't work with a none standard port.

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

Children
No Data