DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Draytek 2820Vn, 2820n and 2830n failing PCI DSS Scan

  • dsimpson1975
  • Topic Author
  • Offline
  • New Member
  • New Member
More
26 Apr 2016 12:24 #1 by dsimpson1975
Just for information if anyone else has problems with PCI DSS Scans.

I have a number of routers mainly 2820Vn, 2820n and 2830n which are failing PCI DSS scans. I have lost count on the number of hours trying to solve PCI DSS scan problems with Draytek routers, mainly SIP, SSL and VPN configurations. It would appears there has been an over sight in Draytek regarding the latest firmware's and testing against PCI DSS criteria.

All my routes have been upgraded to the latest firmware yet they are failing on 2 issues

Predictable TCP Initial Sequence Numbers Vulnerability
and
PoPToP PPTP Negative read() Argument Remote Buffer Overflow Vulnerability

2820Vn, 2820n firmware version 3.3.7.8
2830n firmware version 3.6.8.4

I'm aware from previous board message with the 2850 failing on the same issue and they resolved the problem reverting back to a previous firmware found here
http://www.forum.draytek.co.uk/viewtopic.php?f=2&t=20707&p=85291&hilit=pci+dss#p85291
and I am in the process of testing to see if 3.3.5.2 will pass the PCI DSS scans on the 2820's.

To go through 60+ routers to downgrade is going to be a nightmare and disruption to our stores. Please Draytek, can you sort this issue out.

Just to note, it would be a whole lot better from a security point that all functions are disabled out of the box.

Please Log in or Create an account to join the conversation.

  • dsimpson1975
  • Topic Author
  • Offline
  • New Member
  • New Member
More
27 Apr 2016 15:18 #2 by dsimpson1975
Update....

PCI DSS scan pass on the 2820's using firmware 3.3.5.2

On the 2830 they are passing using firmware 3.6.7. albeit a number of revisions back from the current 3.6.8.4

Please Log in or Create an account to join the conversation.

  • admin2
  • Site Admin
  • Site Admin
More
04 May 2016 10:39 #3 by admin2
I wonder if it's a false positive as I don't think that DrayTek use PoPToP on 2820,2830.

I'd recommend contacting support before downgrading.

Please Log in or Create an account to join the conversation.