We use nessus to scan our network. My most recent scan reports several openssl vulnerabilitis with a cvss score of 9.3, (rated HIGH), see below for details. The products found affected are:
Dell idrac6 1.97
Dell idrac7 1.57.57
Nessus says that the vulnerabilty is confirmed, and the openssl version could also be vulnerable to other openssl issues release on the same day as the OpenSSL 'ChangeCipherSpec' MiTM Vulnerability" released on the 5th of june.
Is this confirmed by dell? will patches be released for this vulnerabilties?
Here is what I received for the Dell Response to Openssl vulnerability.
After a couple of calls to technical support here is what I'm getting for my iDRAC7 getting flagged by Foundstone security scans for the vulnerability CVE-2014-0224:
" The OPEN SSL package used here contains multiple components, the component that is impacted and vulnerable is not being used, other components in this package are being used but aren't vulnerable".
"Dell has determined that the products listed in the attached document are not affected by the vulnerabilities. Some products have leveraged an older (but not vulnerable) OpenSSL module. These could be flagged by a scanner. Dell is currently working on updating the modules to a version that will not be flagged for these issues".
I've also attempted to upload the document, hopefully it can be viewed or downloaded.
ChrisWat
8 Posts
2882
1
Posted August 14th, 2014 08:00
Here is what I received for the Dell Response to Openssl vulnerability.
After a couple of calls to technical support here is what I'm getting for my iDRAC7 getting flagged by Foundstone security scans for the vulnerability CVE-2014-0224:
" The OPEN SSL package used here contains multiple components, the component that is impacted and vulnerable is not being used, other components in this package are being used but aren't vulnerable".
"Dell has determined that the products listed in the attached document are not affected by the vulnerabilities. Some products have leveraged an older (but not vulnerable) OpenSSL module. These could be flagged by a scanner. Dell is currently working on updating the modules to a version that will not be flagged for these issues".
I've also attempted to upload the document, hopefully it can be viewed or downloaded.
If this post has helped you please rate it.
Thanks
[View:~/cfs-file.ashx/__key/communityserver-discussions-components-files/177/2376.Dell_2D00_ResponseOpenSSLSecurityAdvisory_5F00_05_5F00_June_5F00_2014_5F00_final.pdf:550:0]