UNSOLVED

miked420

updated

12 years ago

M

miked420

2 Posts

0

772

November 17th, 2014 07:00

OpenSSL vulnerability

A recent securit scan for our attached SANs show an OpenSSL vulnerability.  Will this firmware upgrade resolve this issue?

CLARiiON CX4-120 : Current FLARE 04.30.000.5.517 upgradable to 04.30.000.5.526.

CLARiiON CX300 : Current FLARE 2.26.300.5.020 upgradable to 2.26.300.5.031.

  • kelleg

    6 Operator

    4537 Posts

    268

    1

    Posted November 18th, 2014 14:00

    I could not find a vulnerability for the CX or CX4, but I did find this notice:

    EMC's responses to this security alert are outlined below:
    EMC Product EMC Product Version(s) EMC Product Impact Impact Status Technical Details

    CLARiiON CX4 Series

    All

    Not Exploitable The EMC product embeds the vulnerable component, but the vulnerability cannot be exploited. RemotelyAnywhere, which embeds OpenSSH on the CLARiiON CX4, does not use "host-based authentication". It does not utilize ssh-keysign.