Ask our Experts
Didn't find what you are looking for? Ask our experts!
New Community Ranking System
Our Community ranking system has recently been updated. You may notice changes in user rankings and receive system messages or notifications. If you have questions about how the new ranking works, please refer to the announcement post for more details (click here).
Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz
Search in
Please select a country to continue with beta search.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2026-04-22 05:47 AM
We’ve received a POA&M related to a security vulnerability and wanted to reach out for your expertise. Our initial research suggests that the issue is linked to the DCE Proprietary Rocky-Linux OS, specifically concerning Python 3.6— has reached end-of-life.
Currently, we are running version 8.1.1 in production, and even the latest release (9.1.1) continues to rely on Proprietary Rocky-Linux 8.10, which includes the same Python 3.6 version. Since Python 3.6 is hard coded at the OS level, patching or updating it isn't possible through the usual channels.
Given these constraints, we’re reaching out to ask for your guidance and recommendations on how best to address this vulnerability moving forward. Any insights or suggestions you can share would be greatly appreciated.
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2026-04-22 10:38 AM
did you have a specific CVE or ERRATA that your security team flagged? Red Hat and Rocky Linux backport security fixes so a package version by itself isn't enough to determine if it is vulnerable.
https://access.redhat.com/solutions/57665
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2026-04-23 08:33 AM
No specifc CVE associated here is the Plugin ID and the output
Plugin ID: 148367
Plugin Output:
The following Python installation is unsupported :
Path : /
Port : 443
Installed version : 2.7.18
Latest version : 3.10
Support dates : 2020-01-01 (end of life)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2026-04-25 07:21 AM
Dear @Irizarrym,
Yes, Rocky Linux 8 (8.10), which is used by the current DCE IT appliance, is far from new and has a significant list of outdated packages. However, since it is a direct clone of RHEL-8, according to the official explanation of https://access.redhat.com/support/policy/updates/errata#RHEL8_Planning_Guide, this OS can still be used until 2029 and will receive all the necessary critical security and functionality fixes. In addition, it should be noted that:
- Packages within RHEL 8, 9, and 10 Application Streams may have a shorter life cycle than a specific RHEL minor release.
- The inclusions list below is a minimum set of packages that apply to Urgent bug fixes.
- bind, bash, chrony, grub2, grubby, glibc, gnutls, httpd, kernel, libgcrypt, libvirt, nss, openssh, openssl, python 3.6 (RHEL 8), python 3.9 (RHEL 9), python 3.12 (RHEL 10), qemu-kvm, rpm, sudo, systemd, wget, yum / dnf
Link copied. Please paste this link to share this article on your social media post.
You’ve reached the end of your document
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.