HPE6-A84 · Question #39
Refer to the scenario. A customer has asked you to review their AOS-CX switches for potential vulnerabilities. The configuration for these switches is shown below: What is one recommendation to make?
The correct answer is D. Create a control plane ACL to limit the sources that can access the switch with SSH. According to the AOS-CX Switches Multiple Vulnerabilities, one of the vulnerabilities (CVE-2021- 41000) affects the SSH service on AOS-CX switches. This vulnerability allows an unauthenticated remote attacker to cause a denial-of-service condition on the switch by sending…
Question
Refer to the scenario. A customer has asked you to review their AOS-CX switches for potential vulnerabilities. The configuration for these switches is shown below:
What is one recommendation to make?
Exhibit
Options
- ALet the RADIUS server confiqure VLANs on LAG 1 dynamically.
- BUse MDS instead of SHA1 for the NTP authentication key.
- CEncrypt the certificate in the TA-profile.
- DCreate a control plane ACL to limit the sources that can access the switch with SSH.
How the community answered
(31 responses)- A3% (1)
- B13% (4)
- C26% (8)
- D58% (18)
Explanation
According to the AOS-CX Switches Multiple Vulnerabilities, one of the vulnerabilities (CVE-2021- 41000) affects the SSH service on AOS-CX switches. This vulnerability allows an unauthenticated remote attacker to cause a denial-of-service condition on the switch by sending specially crafted SSH packets. The impact of this vulnerability is high, as it could result in a loss of management access and network disruption. Therefore, one recommendation to make is to create a control plane ACL to limit the sources that can access the switch with SSH. This way, the switch can filter out unwanted or malicious SSH traffic and reduce the risk of exploitation.
Topics
Community Discussion
No community discussion yet for this question.
