SC Storage Customer Notification: iDRAC BMC Security

Summary: This article explains how BMC and or iDRAC may report network vulnerabilities to scanning software for Storage Center products.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

Summary:
The BMC and or iDRAC may report network vulnerabilities to scanning software for Storage Center products.
 

Problem Detail:
Customers running network vulnerability scanners in their network may see reports that the BMC and or iDRAC interfaces are vulnerable.

BMC and iDRAC firmware are part of the Storage Center Operating System (SCOS) software package and are only available for upgrade in new versions of SCOS. Extensive compatibility testing between these firmware versions and SCOS are performed to ensure that there are no issues between the operating system and the hardware monitoring software. Due to this compatibility testing, SCOS does not always run the latest versions of the BMC and iDRAC which may result in potential network security vulnerability reports.


Affected Versions:
All Storage Centers

Cause

Storage Center does not use all of the functionality of BMC or iDRAC software so most of the security reports are false or not applicable. To check if a security vulnerability has been reported or addressed, go to dell.com/support.

Resolution

Workaround:
Most network switches today have management software which features the ability to enable/disable specific ports. If there is a security concern for your Storage Center that cannot be addressed by upgrading to the latest SCOS version, Dell Technologies recommends that the network switch ports connecting to the BMC or iDRAC on the Storage Center be disabled until needed.

Affected Products

Entry Level & Midrange, Compellent (SC, SCv & FS Series), Dell Compellent SC4020, Dell Storage SC8000, Dell Storage SCv2000, Dell Storage SCv2020, Dell Storage SCv2080, Dell Storage SC5020, Dell Storage SC5020F, Dell Storage SC7020 , Dell Storage SC7020F, Dell Storage SC9000, Dell Storage SCv3000, Dell Storage SCv3020 ...
Article Properties
Article Number: 000129215
Article Type: Solution
Last Modified: 03 ربيع الأول 1447
Version:  4
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.