Security experts at Rapid7 have discovered a security issue in the SSH configuration for Nexpose appliances tracked as CVE-2017-5243. The issue affects all Nexpose devices, owners with root access can fix the problem by editing /etc/ssh/sshd_config file in the appliance to ensure only modern ciphers, key exchange, and MAC algorithms are accepted. The vulnerability could have let an attacker in a position on the network to force an algorithm downgrade between an attacker and the Nexpose appliance during the authentication phase.”]
Source: https://securityaffairs.co/wordpress/59708/hacking/nexpose-appliances-ssh-flaw.html

