Forum Discussion

Senthil_7991's avatar
Senthil_7991
Icon for Nimbostratus rankNimbostratus
Oct 04, 2018

The remote service supports the use of medium strength SSL ciphers.

Hi Team,

 

We recently received this below vulnerabilities for our some of sites, we should know solution to rectify this vulnerabilities, what ciphers needs to apply?.

 

Plugin Name SSL Medium Strength Cipher Suites Supported

 

"Plugin Output: Here is the list of medium strength SSL ciphers supported by the remote server :

 

Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)

 

EDH-RSA-DES-CBC3-SHA         Kx=DH          Au=RSA      Enc=3DES-CBC(168)        Mac=SHA1   
ECDHE-RSA-DES-CBC3-SHA       Kx=ECDH        Au=RSA      Enc=3DES-CBC(168)        Mac=SHA1   
DES-CBC3-SHA                 Kx=RSA         Au=RSA      Enc=3DES-CBC(168)        Mac=SHA1   

The fields above are :

 

{OpenSSL ciphername} Kx={key exchange} Au={authentication} Enc={symmetric encryption method} Mac={message authentication code} {export flag}"