Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PCI Compliance - OpenSSH 4.3 is vulnerable Severity: Critical Problem

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 2 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      ghurty
      last edited by

      Hi,

      I have to run PCI compliance on one of my pfsense routers (1.2.3).

      I am getting back a fail:
      PCI Compliance - OpenSSH 4.3 is vulnerable Severity: Critical Problem

      How do I disable openssh from remote access or how do I upgrade it?

      Thanks

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Upgrade to a current supported release, 2.0.1.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • G
          ghurty
          last edited by

          Thank you.

          Quick question.

          I am currently at a remote location and have access to the box via VPN. Am I able to safely upgrade that way, or does it have to be done locally.

          Thanks

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            It depends on the status of the box (full install vs NanoBSD, etc) but in general that works OK. Read the upgrade guide on the wiki. Be sure to check the config as suggested there.

            I have done remote upgrades on even NanoBSD installs using console upgrade by URL that went from 1.2.3-RC1 up to 2.0.1-RELEASE without issues.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.