I show that 1.65 was the last firmware update released for the DRAC 5. I was unable to find any mention of CVE-2009-3095 in any of our updates or statements.
Most detected vulnerabilities in relation to the Apache server on our DRACs are false positives. The Apache server running on the DRAC does not have full functionality. Most of the security alerts just check if Apache is running and what version it is. They do not perform penetration tests to see if the device is actually vulnerable.
I can't say for sure if the DRAC5 is vulnerable to this type of attack. The DRAC5 has been end-of-life for several years, and even if it was vulnerable it is unlikely we will ever release another firmware update for the DRAC5. 1.65 looks to be the last firmware update it will receive.
Daniel My
12 Elder
•
6205 Posts
3181
0
Posted April 6th, 2018 10:00
Hello
Please send a private message with your service tag to ensure we have all appropriate information on your system.
Thanks