AzureArc Gateway VM SWEET32 vulnerability

AZR-GP 20 Reputation points
2025-03-17T12:55:04.7566667+00:00

The local AzureArc Resource Gateway VM that is deployed to link AzureARC to vCenter is showing up in scans with a SWEET32 vulnerability. How can we change the cipher suite used to resolve this?

Thanks

Azure Arc
Azure Arc
A Microsoft cloud service that enables deployment of Azure services across hybrid and multicloud environments.
504 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Naveena Patlolla 1,900 Reputation points Microsoft External Staff
    2025-03-20T20:39:59.3633333+00:00

    Hi @AZR-GP

    The Azure Arc Resource Gateway VM, which facilitates the connection between Azure Arc and vCenter.

    To mitigate the SWEET32 vulnerability in your Azure Arc Resource Gateway VM, you need to disable or remove 3DES cipher suites from the TLS/SSL configuration and use stronger encryption algorithms like AES instead as per your Security or Exclude the server from scan (Not Recommended) 

    Important Considerations:

    Contact Microsoft Support: Since the Azure Arc Resource Gateway VM is a Microsoft-developed appliance, it's crucial to contact with Microsoft Support before making any configuration changes to ensure compliance with support agreements and to receive guidance tailored to your specific setup.

    Please do not forget to "Accept the answer” wherever the information provided helps you, this can be beneficial to other community members.it would be greatly appreciated and helpful to others.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.