DSA-2024-322: Security Update for Dell Precision Rack for an iDRAC9 OpenSSH Vulnerability

Summary: Dell iDRAC9 with Lifecycle Controller remediation for Dell Precision Rack is available for an OpenSSH Vulnerability that could be exploited by malicious users to compromise the affected system. ...

Ez a cikk a következő(k)re vonatkozik: Ez a cikk nem vonatkozik a következő(k)re: Ez a cikk nem kapcsolódik egyetlen konkrét termékhez sem. Ez a cikk nem azonosítja az összes termékverziót.

Impact

High

Details

Third-party Component CVEs More information
OpenSSH CVE-2024-6387

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Érintett termékek és helyreállítás

Product Affected Versions Remediated Versions Release Date
(MM/DD/YYYY)
Link
Precision 7920 Rack iDRAC9 firmware version prior to 7.00.00.173 iDRAC9 firmware version 7.00.00.173 or later 08/27/2024
 
iDRAC 7.00.00.173 | Driver Details
 
7920 XL Rack iDRAC9 firmware version prior to 7.00.00.173 iDRAC9 firmware version 7.00.00.173 or later 08/27/2024 iDRAC 7.00.00.173 | Driver Details
Precision 7960 Rack iDRAC9 firmware version prior to 7.10.70.00 iDRAC9 firmware version 7.10.70.00 or later 09/24/2024 iDRAC 7.10.70.00 | Driver Details
 
Precision 7960 XL Rack iDRAC9 firmware version prior to 7.10.70.00 iDRAC9 firmware version 7.10.70.00 or later 09/24/2024 iDRAC 7.10.70.00 | Driver Details
Product Affected Versions Remediated Versions Release Date
(MM/DD/YYYY)
Link
Precision 7920 Rack iDRAC9 firmware version prior to 7.00.00.173 iDRAC9 firmware version 7.00.00.173 or later 08/27/2024
 
iDRAC 7.00.00.173 | Driver Details
 
7920 XL Rack iDRAC9 firmware version prior to 7.00.00.173 iDRAC9 firmware version 7.00.00.173 or later 08/27/2024 iDRAC 7.00.00.173 | Driver Details
Precision 7960 Rack iDRAC9 firmware version prior to 7.10.70.00 iDRAC9 firmware version 7.10.70.00 or later 09/24/2024 iDRAC 7.10.70.00 | Driver Details
 
Precision 7960 XL Rack iDRAC9 firmware version prior to 7.10.70.00 iDRAC9 firmware version 7.10.70.00 or later 09/24/2024 iDRAC 7.10.70.00 | Driver Details
iDRAC patched the version of OpenSSH embedded inside of it. The iDRAC OpenSSH banner will continue to report 9.6p1 and may be reported as a false positive by network scanning tools. To verify that a patched version of iDRAC is running use the iDRAC firmware version as indicated above.

Megkerülési lehetőségek és kockázatcsökkentés

CVE ID Workaround and Mitigation
CVE-2024-6387 For iDRAC9 workaround, disable SSH on iDRAC.

This can be done in the iDRAC Web interface by navigating to Overview > iDRAC > Settings > Network > Services.

More details can be found at the iDRAC 9 User Guide

Revision History

RevisionDateDescription
1.02024-09-24Initial Release

Related Information

Érintett termékek

7920 XL Rack, Precision 7960 XL Rack, Precision 7920 Rack, Precision 7960 Rack
Termék tulajdonságai
Article Number: 000227007
Article Type: Dell Security Advisory
Utoljára módosítva: 24 szept. 2024
Választ kaphat kérdéseire más Dell-felhasználóktól
Támogatási szolgáltatások
Ellenőrizze, hogy a készüléke rendelkezik-e támogatási szolgáltatással.