Unsolved

This post is more than 5 years old

1 Message

1614

June 25th, 2019 13:00

Disable RSA in iDRAC 7

Hi,

We received a notification from our SIEM that our idrac has the ROBOT Attack vulnerability over TCP port 443. It was recommended to disable RSA  encryption. While I'm not totally convinced this is the solution to the issue, I am reaching out to see where I could begin to remediate the vulnerability?

Our PowerEdge T320 is currently running idrac 7  version 2.61.60.60. Has anyone seen this vulnerability on the idrac? Has anyone fixed it? 

12 Elder

 • 

6.2K Posts

June 25th, 2019 15:00

Hello

There may have been changes with more recent firmware. You should probably get the firmware updated and test again.

It looks like it is triggering on the web server. I think you can change the ciphers used by the web server, but it may only be configurable via command line. The latest manuals are on the 2.60.60.60 firmware support page.

http://www.dell.com/idracmanuals/

Thanks

January 6th, 2020 09:00

I would also like to see a solution to this as we are getting the TLS ROBOT Severity 4 vulnerability reported on the RSA ciphers.

No Events found!

Top