OneFS: security scans for SSH show older versions
Summary: Doing banner or tool scraping security scans are not always effective and cannot account for backported fixes.
Symptoms
OneFS PowerScale, like a wide array of products and solutions, uses SSH-based logins for a variety of functions.
Attempting to do basic or rote scanning of OneFS to examine SSH may return inaccurate results from security scanners claiming exposure to security vulnerabilities already addressed.
Cause
Dell, like many other vendors, utilizes backporting for fixing numerous security related issues. This means that when Dell determines a security matter (such as a CVE) must be addressed in SSH, it is sometimes done without updating the visible, presented version of SSH that scanners or SSH client tools can detect.
Your scan or connection may say your SSH is presenting as version XYZ, but that is never authoritative over what fixes are or are not present in your OneFS installation.
Any vendor (such as a security vendor) claiming that presented version is specifically authoritative over our internal code, patching, and bug remedies is completely wrong. This manner of backporting is a completely normal information technology and information security related practice, widely used in our industry.
Resolution
All customers are encouraged to go here:
https://www.dell.com/support/security/en-us
And ideally subscribe for Dell Security Alerts (DSAs) with a suitable role account that will deliver alerts to all involved stakeholders with a security or administrative role over your PowerScale OneFS installations.
All CVEs and similar issues addressed in SSH will be listed to the degree that can be shared with the public there.
If you need additional clarity or clarification, please open a new Support ticket for your OneFS insallation, and be sure on your submission to include the complete full security scanner report that generated the warnings for you.