Can you please send me the info also about the vulnerabilities for the DRAC and openssl? Our auditors are hounding us for results. I have seen any updates for a DRAC 5 in a very long time and the latest firmwares for both DRAC 6 and DRAC 7 still show as vulnerable.
I'm having the same issue. I've applied the latest iDRAC7 firmware - 1.66.65 (Build 07), but the iDRAC is still showing up as vulnerable for these CVEs.
I also need firmware to resolve CVE-2014-0224, CVE-2014-0221, CVE-2014-0195, CVE-2014-0198, CVE-2010-5298, CVE-2014-3470, CVE-2014-0076 on a number of DRAC5 and iDRAC6. It is being picked up by Qualys QID 38602. Please email me a link to the fix and/or any updated information on this issue.
I was running 2.10.10.10 for the last few months and just upgraded to 2.20.20.20. I've not had any failed scans since the 2.10.10.10 update.
You probably also want to set your SSL encryption to 256-bit if you haven't done so. Something was getting flagged for that too until I changed it.
GUI login, iDRAC Settings, Network, Services, Web Server SSL Encryption and set to 256-bit or higher option.
I just upgrade some of my self-signed certificates to CA signed, 2048-bit SHA-2 certificates. While I'm not getting scan errors (yet), my browsers complain that the ciphers are obsolete. I don't see any way to change those settings with GUI or racadm.
We had similar warnings from our security scans for other servers. The vulnerability that was reported only existed if a deprecated command is available and it was not used on our systems.
swspjcd
1 Rookie
•
51 Posts
0
April 1st, 2015 12:00
Can you please send me the info also about the vulnerabilities for the DRAC and openssl? Our auditors are hounding us for results. I have seen any updates for a DRAC 5 in a very long time and the latest firmwares for both DRAC 6 and DRAC 7 still show as vulnerable.
rwhalen3
4 Posts
0
April 2nd, 2015 14:00
I'm having the same issue. I've applied the latest iDRAC7 firmware - 1.66.65 (Build 07), but the iDRAC is still showing up as vulnerable for these CVEs.
When will an updated firmware be released?
BrianStrain
2 Posts
0
April 21st, 2015 14:00
New firmware available 2.10.10.10
This release supports both iDRAC7 and iDRAC8
http://en.community.dell.com/techcenter/systems-management/w/wiki/7526.idrac7-home
ltigges
2 Posts
0
May 20th, 2015 17:00
I also need firmware to resolve CVE-2014-0224, CVE-2014-0221, CVE-2014-0195, CVE-2014-0198, CVE-2010-5298, CVE-2014-3470, CVE-2014-0076 on a number of DRAC5 and iDRAC6. It is being picked up by Qualys QID 38602. Please email me a link to the fix and/or any updated information on this issue.
ltigges
2 Posts
1
July 15th, 2015 11:00
We have verified firmware 3.75 released 25 Jun 2015 fixes it on iDRAC 6. Thanks Dell!
http://www.dell.com/support/home/us/en/19/Drivers/DriversDetails?driverid=GR09H
Ricado352
2 Posts
0
September 9th, 2015 15:00
I am using iDRAC 7. Has Dell confirmed that version 1.66.65 or 2.10.10.10 fixes the issue?
Tim-UMD
6 Posts
0
September 24th, 2015 10:00
I was running 2.10.10.10 for the last few months and just upgraded to 2.20.20.20. I've not had any failed scans since the 2.10.10.10 update.
You probably also want to set your SSL encryption to 256-bit if you haven't done so. Something was getting flagged for that too until I changed it.
GUI login, iDRAC Settings, Network, Services, Web Server SSL Encryption and set to 256-bit or higher option.
I just upgrade some of my self-signed certificates to CA signed, 2048-bit SHA-2 certificates. While I'm not getting scan errors (yet), my browsers complain that the ciphers are obsolete. I don't see any way to change those settings with GUI or racadm.
Ricado352
2 Posts
1
September 30th, 2015 17:00
Thanks. It worked.
tstonemadisoncollege
1 Rookie
•
14 Posts
0
October 6th, 2015 11:00
We had similar warnings from our security scans for other servers. The vulnerability that was reported only existed if a deprecated command is available and it was not used on our systems.
voofer
1 Message
0
December 23rd, 2015 13:00
This issue is coming up again. What is the status ?
Bergamini
1 Message
0
May 23rd, 2016 12:00
Hi. Can you also email the information to me? Thanks. grbergamini@gmail.com
donjohnson86
1 Message
0
October 13th, 2016 12:00
Hello, I need the email as well please.