NOcius720147 (Community Member) asked a question.

I would like to know if there is a fix for the CWE 757 Selection of Less-Secure ALgorithm During Negotiation (Algorithm Downgrade)?

I would like to know if there is a fix or how to remediate the CWE 757 Selection of Less-Secure ALgorithm During Negotiation (Algorithm Downgrade).

 

TLSv1.2 cipher TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384

TLSv1.2 cipher TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA256

 

I got the result from the dynamic analysis scan. and as per our dev team, they have already set to latest security policy (ELBSecurityPolicy-FS-1-2-Res-2019-08) in AWS end. is this enough? there is no options to disable CBC and keep GCM alone.

 

I advised them to disable the entire cipher suites with CBC. But according to them, Unlike traditional system AWS(alb) is not having option to disable/enable specific cipher.

 

Thank you.


Bill T likes this.

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.