Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000063455


List of Avamar hardware vulnerabilities resolved in Firmware update

Summary: List of Avamar hardware vulnerabilities resolved in Firmware update

Article Content


Symptoms



A security scan can highlight a data node or utility node Remote Access (RMM) port as having a security vulnerability.
The following tables show the known vulnerabilities and recommended firmware level to remedy these issues in Gen4S and Gen4T hardware.

Cause

NA

Resolution

Gen4T
 
Vulnerability Min Firmware Level
CVE-2016-2183 BMC 24.10
CVE-2013-2566 BMC 24.10
CVE-2015-2808 BMC 24.10
CVE-2014-3566 BMC 24.10
To disable SSL 2.0 and 3.0 BMC 24.10


To verify firmware level on Gen4T nodes:
showfwvers


Gen4S

Vulnerability Min Firmware Level
CVE-2016-2183 BMC 1.27
CVE-2013-2566 BMC 1.25
CVE-2015-2808 BMC 1.25
CVE-2012-4929 BMC 1.25
CVE-2012-4930 BMC 1.25
To disable support for TLS 1.0 BMC 1.28
To disable SSL 2.0 and 3.0. BMC 1.28

To verify the firmware level on Gen4S nodes:
flashupdt -i | egrep "Op Code|BIOS Version"


To schedule a firmware update, please open a Service Request.

Additional Information

This content is translated in 17 languages: 
https://downloads.dell.com/TranslatedPDF/CS_KB541448.pdf
https://downloads.dell.com/TranslatedPDF/DA_KB541448.pdf
https://downloads.dell.com/TranslatedPDF/DE_KB541448.pdf
https://downloads.dell.com/TranslatedPDF/ES-XL_KB541448.pdf
https://downloads.dell.com/TranslatedPDF/FI_KB541448.pdf
https://downloads.dell.com/TranslatedPDF/FR_KB541448.pdf
https://downloads.dell.com/TranslatedPDF/IT_KB541448.pdf
https://downloads.dell.com/TranslatedPDF/JA_KB541448.pdf
https://downloads.dell.com/TranslatedPDF/KO_KB541448.pdf
https://downloads.dell.com/TranslatedPDF/NL_KB541448.pdf
https://downloads.dell.com/TranslatedPDF/NO-NO_KB541448.pdf
https://downloads.dell.com/TranslatedPDF/PL_KB541448.pdf
https://downloads.dell.com/TranslatedPDF/PT-BR_KB541448.pdf
https://downloads.dell.com/TranslatedPDF/RU_KB541448.pdf
https://downloads.dell.com/TranslatedPDF/SV_KB541448.pdf
https://downloads.dell.com/TranslatedPDF/TR_KB541448.pdf
https://downloads.dell.com/TranslatedPDF/ZH-CN_KB541448.pdf

Article Properties


Affected Product

Avamar

Product

Avamar, Avamar Data Store, Avamar Data Store Gen4S, Avamar Data Store Gen4T

Last Published Date

18 Dec 2020

Version

3

Article Type

Solution