Forum Discussion

S_Meulmeester's avatar
Sep 11, 2019

Vulnerability OpenSSH >= 2.3.0 AllowTcpForwarding Port Bouncing : CVE-2004-1653

I get from the PCI audit following issue to solve for F5 LTM BIG-IP 13.1.0.8 Build 0.0.3

 

OpenSSH >= 2.3.0 AllowTcpForwarding Port Bouncing : CVE-2004-1653

According to its banner, the remote host is running OpenSSH, version 2.3.0 or later.  Such versions of OpenSSH allow forwarding TCP connections. 

If the OpenSSH server is configured to allow anonymous

 

Is this a vulnerability for F5 and is there a way to fix it ?

 

No RepliesBe the first to reply