Clarification on Nessus Plugin 298387 ("Shor's Harvest Now Decrypt Later") for Carbon Black EDR.
search cancel

Clarification on Nessus Plugin 298387 ("Shor's Harvest Now Decrypt Later") for Carbon Black EDR.

book

Article ID: 450543

calendar_today

Updated On:

Products

Carbon Black EDR

Issue/Introduction

Nessus scan reports "Shor's Harvest Now Decrypt Later" on Carbon Black Endpoint Detection and Response (EDR) servers.

Environment

CB EDR 7.9.x

Resolution

Nessus plugin 298387 ("Shor's Harvest Now Decrypt Later," see https://www.tenable.com/plugins/nessus/298387   ) is not a CVE — it is a generic, forward-looking advisory that flags any TLS/SSH service using standard asymmetric cryptography (RSA/ECDH) as theoretically vulnerable to a future cryptographically-relevant quantum computer, and it fires on virtually any TLS-based service today. CBEDR Server 7.9.1-svr on RHEL 8.10 uses standard TLS 1.2/1.3 with classical cipher suites, which is expected and correct for this platform — RHEL 8.10 has no post-quantum cryptography support at all (per Red Hat, https://access.redhat.com/articles/7119430  , PQC only arrives in RHEL 10.1+), so no OS-level or product-level mitigation is currently possible. No code, configuration, or vendor action applies. 
 
 
 
 
Recommended disposition: No impact.