Resolving InsightVM reported vulnerabilities with NCPA
Posted: Thu Dec 09, 2021 9:50 pm
NCPA client on windows (port 5693) reports the following
SERVICES
Service Name Product Port Protocol Vulnerabilities Users Groups Authentication
HTTPS ajenti 5693 TCP 4 0 0 Unknown
--
Vulnerability Severity Instances
Untrusted TLS/SSL server X.509 certificate Severe 1
TLS/SSL Server Supports The Use of Static Key Ciphers Moderate 1
Self-signed TLS/SSL certificate Severe 1
HTTP OPTIONS Method Enabled Moderate 1
--
OPTIONS method returned values including itself
--
Negotiated with the following insecure cipher suites:
TLS 1.2 ciphers:
TLS_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_AES_128_CBC_SHA256
TLS_RSA_WITH_AES_128_GCM_SHA256
TLS_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_AES_256_CBC_SHA256
TLS_RSA_WITH_AES_256_GCM_SHA384
TLS_RSA_WITH_CAMELLIA_128_CBC_SHA
TLS_RSA_WITH_CAMELLIA_256_CBC_SHA
--
Can I use domain signed certs on the product? (maybe a silly question, but curious) -- I see where the .crt exists in program files/nagios/ncpa/var. "This is an unsupported workflow" is an OK answer.
Can I turn off the RSA ciphers on the webserver?
Can I turn off HTTP Options on the webserver?
SERVICES
Service Name Product Port Protocol Vulnerabilities Users Groups Authentication
HTTPS ajenti 5693 TCP 4 0 0 Unknown
--
Vulnerability Severity Instances
Untrusted TLS/SSL server X.509 certificate Severe 1
TLS/SSL Server Supports The Use of Static Key Ciphers Moderate 1
Self-signed TLS/SSL certificate Severe 1
HTTP OPTIONS Method Enabled Moderate 1
--
OPTIONS method returned values including itself
--
Negotiated with the following insecure cipher suites:
TLS 1.2 ciphers:
TLS_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_AES_128_CBC_SHA256
TLS_RSA_WITH_AES_128_GCM_SHA256
TLS_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_AES_256_CBC_SHA256
TLS_RSA_WITH_AES_256_GCM_SHA384
TLS_RSA_WITH_CAMELLIA_128_CBC_SHA
TLS_RSA_WITH_CAMELLIA_256_CBC_SHA
--
Can I use domain signed certs on the product? (maybe a silly question, but curious) -- I see where the .crt exists in program files/nagios/ncpa/var. "This is an unsupported workflow" is an OK answer.
Can I turn off the RSA ciphers on the webserver?
Can I turn off HTTP Options on the webserver?