Discussions
ScanAlert Vulnerability - Weak Supported SSL Ciphers Suites
We also received this vulnerability:
<<Description
The remote host supports the use of SSL ciphers that offer either weak encryption or no encryption at all. This vulnerability is valid for all SSL/TLS sessions that are passing sensitive information.
PCI defines strong cryptography, for secret key based systems, as anything above 80 bit encryption.
General Solution
Important Note: Weak ciphers can run on other service ports as well. Typical ports include: 465, 993, 995, 2078, 2083, 2087, 2096, 8443, etc. Each application will have its own configuration options to handle weak ciphers.
Consult the documentation specific to each application on how to disable them. Some knowledge base articles are listed below. Successful configuration will cause this vulnerability to drop off automatically after the next scan. If the vulnerability does not go away, verify the service port in question and review the related documentation.