NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

jpotts2012's avatar
jpotts2012
Follower
May 14, 2020
Status:
New Idea

Remove TLS 1.0 from current device firmware

It has come to my attention that the Netgear R6700v3 with firmware v1.0.2.52_1.0.39 is still running TLS 1.0 and will create flags for PCI Security Scans.  I suggest removing this TLS v1.0.

Other PCI Security Scan Results that are an issues that I have run into and need to be resolved are:

1) Block cipher algorithms with block size of 64 bits

2) Insecure SHA-1 Certificate Signature Algorithm 

3) SSL Certificate Public Key Too Small

4) SSL Certificate signed using a weak hashing algorithm 

5) SSL RC4-based Ciphers Supported

6) SSL/TLS Weak Encryption Algorithms

7) SSLv2, SSLv3 and TLS v1.0 Vulnerable to CBC Attacks

 

Aditionally a 3rd party SSL Certificate needs to able to be added for better security.

 

No CommentsBe the first to comment