Vulnerability - 11827 :: HTTP Security Header Not Detected
Hi all,
Hopefully you can help me with below vulnerability.
The IDRAC versions are 7 and 8 with the firmware version 2.60 and 2.50 respectively.
11827 :: HTTP Security Header Not Detected . We have been flagged for this vulnerability on Qualys Guard scans, could you please advise how we should proceed to fix this.
The latest iDRAC update, 2.63.60.62, included some changes for security. You might consider updating and seeing if the vulnerability you're seeing is resolved.
This feature is currently available in the latest iDRAC9 release. The fix for iDRAC8 will be coming later this fall; the version we are targeting is 2.70.70.70
Please fix the fan speed issue introduced in 2.70.70.70 or the UEFI3015 hit error if it is rolled back to a version prior that doesn't have that speed issue. The 100% increase in noise is driving my client nuts. If I rollback the version the noise goes back to normal but the servers get the hit UEFI0315 error, hit to continue. Rolling the bios back from 2.81 doesn't change anything either,
I've advised them to seek legal action against Dell if they feel they can't get this resolved otherwise. They are aware of Dell's position on non-certified drives but they consider the near doubling of fan speeds and subsequent noise increase to be harassment for not buying Dell products, and a violation of both good-faith, consumer protection, and Anti-Trust laws. E.g., Honda, Toyota etc can't tell a car owner that unless they use Honda, Toyota certified car washes and waxes, etc., that if the paint fails it is the owner's problem. I am told that would be an anti-trust and consumer protection act violation. Just fix whatever that is broken in 2.70.70.70
Kent - I do understand that fan noise can be an issue. But in order to fully understand the situation, I will need a lot more details. Please have your client open up a ticket with Tech Support. This will provide us with the details necessary to assist.
Dell-DylanJ
6 Operator
•
2924 Posts
6863
0
Posted July 2nd, 2019 07:00
Hello,
The latest iDRAC update, 2.63.60.62, included some changes for security. You might consider updating and seeing if the vulnerability you're seeing is resolved.