Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Insufficient DH Group Strength Vulnerability

    Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
    9 Posts 4 Posters 4.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sai ravi
      last edited by

      Hi
            When we did a vulnerability assessment on our PFSense firewall we could see the below vulnerability being reported during the scan.

      " SSL Diffie-Hellman Key Exchange Insufficient DH Group Strength Vulnerability"

      Is there any recommended solution or workaround for closing this vulnerability on pfsense?

      Any help is much appreciated.

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by

        Not with this amount of info, no. Blindly running scans without understanding what's being done and what's the output about is not exactly productive.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          What did you scan?  What service came back with that?  Are you running say HAproxy or something?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • S
            sai ravi
            last edited by

            Hi
                  It is occurring on the port 4443, a custom port number for web configurator (Web GUI). Also have appended the vulnerability results.

            Medium (CVSS: 4.0)
            NVT: SSL Diffie-Hellman Key Exchange Insufficient DH Group Strength Vulnerability

            Port
            4443

            Summary
            The TLS service uses Diffie-Hellman groups with insufficient strength (key size ¡ 2048).

            Vulnerability Detection Result
            Server Temporary Key Size: 1024 bits

            Also when i searched i could see some workaround in generic as "Deploy (Ephemeral) Elliptic-Curve Diffie-Hellman (ECDHE)".

            But not sure whether the same can be applied for PFSense.

            1 Reply Last reply Reply Quote 0
            • D
              doktornotor Banned
              last edited by

              No idea if using outdated pfSense or the (still unknown) scanner produces complete BS. - https://github.com/pfsense/pfsense/blob/RELENG_2_3_2/src/etc/inc/system.inc#L1340

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                what version of pfsense are you running.. As dok pointed out this has been updated quite some time ago..

                I just ran a scan against my pfsense 2.3.2_p1

                dhlength.png
                dhlength.png_thumb

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • S
                  sai ravi
                  last edited by

                  Hi
                        We are using pfsense 2.2.4.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    So your worried about security and running a version that came out in July of 2015 ;)  Makes a lot of sense… doh!!!

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • KOMK
                      KOM
                      last edited by

                      Time to upgrade.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.