@skilledinept said in Do the OpenSSH 7.9 CVEs apply to pfSense?:
-to see how readily is info like this available to scanner.
you could turn off the banner, Not sure if pfsense allows for that in the gui? But if your allowed to talk to the ssh and try and negotiate a connection to "auth" you would still be able to get info like what algos and ciphers are possible.
You could edit the sshd conf directly, but that would just get reverted on update, etc.
Security scanners can be very useful - and fun even. But a lot of what they report really needs to be taken with a grain of salt, if not a whole freaking tablespoon of it ;)
But it did do its job - it got you curious, and looking into, and now you prob make for a more secure setup even if what it had reported wasn't really valid ;)