PMG Medium Severity Vulnerabilities

antonin.chadima

Active Member
Sep 22, 2021
34
7
28
51
Hi,
We receive this notification from our internet provider on a regular basis:

Port 25/tcp

SSL Anonymous Cipher Suites Supported

The remote host supports the use of anonymous SSL ciphers. While this enables an administrator to set up a service that encrypts traffic without having to generate and configure SSL certificates, it offers no way to verify the remote host's identity and renders the service vulnerable to a man-in-the-middle attack.
CVE-2007-1858 BID-28482 URL NSS-31705

TLS Version 1.0 Protocol Detection
The remote service accepts connections encrypted using TLS 1.0. TLS 1.0 has a number of cryptographic design flaws. Modern implementations of TLS 1.0 mitigate these problems, but newer versions of TLS like 1.2 and 1.3 are designed against these flaws and should be used whenever possible.
CWE-327 URL NSS-104743

TLS Version 1.1 Deprecated Protocol
The remote service accepts connections encrypted using TLS 1.1. TLS 1.1 lacks support for current and recommended cipher suites. Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1.
CWE-327 URL URL NSS-157288

Any solution for PMG 9.1.0?
 
Last edited: