cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
332
Views
0
Helpful
2
Replies

Expressway Weak Cipher vulnerability

iverson.justin
Level 1
Level 1

Our security team is alerting us of a Cipher Block Chaining (CBC) ciphers detected (low-severity finding) on our expressways. Would updating our ciphers to the recommended Resolve this issue?   https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/admin_guide/X14-2/exwy_b_cisco-expressway-administrator-guide-x142/exwy_m_managing-security-x142.html?bookSearch=true#reference_4DBB857A1F1924E36837753778780546
EECDH:EDH:HIGH:-AES256+SHA:!MEDIUM:!LOW:!3DES:!MD5:!PSK:!eNULL:!aNULL:!aDH

TAC informed us we should run command xConfiguration SIP Advanced SipTlsDhKeySize: 2048    as well.  

2 Replies 2

b.winter
VIP
VIP

If you already have / had a TAC case open, why you still ask your question here in the forum? And why don't you ask the question to the TAC technician directly?

And yes: change the ciphers, to not include the weak ciphers anymore.

b.winter
VIP
VIP

@iverson.justin Any update?