Forum Discussion
ckajit
May 16, 2022Copper Contributor
SSL Cipher Block Chaining Cipher Suites Supported
Hello,
Environment Exchange 2016 and windows 2012 R2
TLS 1.0 and TLS 1.1 is disabled and only TLS 1.2 is enabled.
Below registry keys are present
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\.NETFramework\v4.0.30319]
"SystemDefaultTlsVersions"=dword:00000001
"SchUseStrongCrypto"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319]
"SystemDefaultTlsVersions"=dword:00000001
"SchUseStrongCrypto"=dword:00000001
Vulnerability scan reports :
Name :SSL Cipher Block Chaining Cipher Suites Supported
Synopsis : The remote service supports the use of SSL Cipher Block Chaining
ciphers, which combine previous blocks with subsequent ones.
Description : The remote host supports the use of SSL ciphers that operate in Cipher
Block Chaining (CBC) mode. These cipher suites offer additional
security over Electronic Codebook (ECB) mode, but have the potential to
leak information if used improperly.
Could you please advise what are next steps
No RepliesBe the first to reply