PowerStore:漏洞回報 HSTS 遺失,但未強制執行
Summary: 漏洞掃描程式報告 HTTP 嚴格傳輸安全性 (HSTS) 遺失或未偵測到 HTTP 安全性標頭
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
此漏洞警示已於 Qualys 和 Nessus 掃描器中的 PowerStore 回報: Qualys Identifier (QID) 11827 "HTTP Security Header Not Detected"Nessus 84502 "The remote web server is not enforcing HSTS."Nessus 142960 "HSTS Missing From HTTPS Server (RFC 6797)"
Cause
HTTP 嚴格傳輸安全 (HSTS) 是一個可選的回應標頭,可以在伺服器上配置它以指示瀏覽器僅通過 HTTPS 進行通信。缺乏HSTS允許降級攻擊,SSL剝離中間人攻擊,並在使用HTTP時削弱cookie劫持保護。
Resolution
僅使用 HTTPS 時,沒有重定向,因此不需要 HSTS。這是偽陽性,當 HTTP 至 HTTPS 重新導向停用時,將不適用於 PowerStore。這是使用我們的安全最佳實踐文檔建議的配置。
HTTP 至 HTTPS 重新導向預設為停用:
PowerStore 安全性組態指南
第 63 頁 停用 HTTPS 重新導向後,僅會公開 HTTPS,並封鎖
HTTP (連接埠 80)。出於安全目的,不支援 HTTP。 啟用 HTTP 重新導向至 HTTPS 功能,可讓前往 PowerStore Manager 的使用者自動從 HTTP 重新導向:要 https://。但是,啟用 HTTP 重新導向的安全性不如讓使用者在 PowerStore Manager 登入時輸入完整的 https:// 位址。
啟用或停用 HTTP 重新導向至 HTTPS 功能是整個叢集的作業。
HTTP 至 HTTPS 重新導向預設為停用:
PowerStore 安全性組態指南
第 63 頁 停用 HTTPS 重新導向後,僅會公開 HTTPS,並封鎖
HTTP (連接埠 80)。出於安全目的,不支援 HTTP。 啟用 HTTP 重新導向至 HTTPS 功能,可讓前往 PowerStore Manager 的使用者自動從 HTTP 重新導向:要 https://。但是,啟用 HTTP 重新導向的安全性不如讓使用者在 PowerStore Manager 登入時輸入完整的 https:// 位址。
啟用或停用 HTTP 重新導向至 HTTPS 功能是整個叢集的作業。
Additional Information
Affected Products
PowerStore 1000X, PowerStore 1000T, PowerStore 1200T, PowerStore 3000X, PowerStore 3000T, PowerStore 3200T, PowerStore 5000X, PowerStore 5000T, PowerStore 500T, PowerStore 5200TProducts
PowerStore 7000X, PowerStore 7000T, PowerStore 9000X, PowerStore 9000T, PowerStore 9200TArticle Properties
Article Number: 000222071
Article Type: Solution
Last Modified: 25 Jul 2025
Version: 3
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.