[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-96922-0

Platform: cpe:/o:microsoft:windows_11Date: (C)2022-05-07   (M)2023-07-04



This policy setting determines the cipher suites used by the SMB server. If you enable this policy setting, cipher suites are prioritized in the order specified. If you enable this policy setting and do not specify at least one supported cipher suite, or if you disable or do not configure this policy setting, the default cipher suite order is used. SMB 3.11 cipher suites: AES_128_GCM AES_128_CCM SMB 3.0 and 3.02 cipher suites: AES_128_CCM How to modify this setting: Arrange the desired cipher suites in the edit box, one cipher suite per line, in order from most to least preferred, with the most preferred cipher suite at the top. Remove any cipher suites you don't want to use. Note: When configuring this security setting, changes will not take effect until you restart Windows. Countermeasure: Enable this policy setting and arrange the desired cipher suite order. Potential Impact: One or more of the cipher suites in the cipher suite order may be not supported.


Parameter:

[cipher suite order]


Technical Mechanism:

(1) GPO: Computer Configuration\Administrative Templates\Network\Lanman Server\Cipher suite order (Lanman Server) (2) REG: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\LanmanServer!CipherSuiteOrder

CCSS Severity:CCSS Metrics:
CCSS Score : 7.7Attack Vector: NETWORK
Exploit Score: 2.2Attack Complexity: HIGH
Impact Score: 5.5Privileges Required: NONE
Severity: HIGHUser Interaction: NONE
Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:LScope: UNCHANGED
 Confidentiality: HIGH
 Integrity: HIGH
 Availability: LOW
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:79367


OVAL    1
oval:org.secpod.oval:def:79367
XCCDF    1
xccdf_org.secpod_benchmark_general_Windows_11

© SecPod Technologies