EcoStruxure IT forum
Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-02 03:06 PM . Last Modified: 2024-04-09 03:58 AM
Hi ,
Our customer used the security scan our DCE server and detect weak point :
TLS/SSL RC4 issue , does our newest version can solve this issue ?
Best Regards
(CID:100340714)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-02 03:06 PM . Last Modified: 2024-04-09 03:58 AM
Hi Chu,
If there is a specific vulnerability, can you please specify? For instance, 7.2.7 resolved CVE-2015-0235. Also, please specify what you are using for the scan. Providing the scan output would be helpful as well. I have found nothing specific to TLS/SSL RC4 but that does not mean it has or has not been addressed. I will look into that on my side.
Steve
(CID:100340830)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-02 03:06 PM . Last Modified: 2024-04-09 03:58 AM
Hi Steven , They used McAfee mvm to scan our DCE server , The message like as below: The encryption kit of TLS/SSL RC4 expose the vulnerability ,it's should be disable . Hope this can useful , thank u . Best Regards
(CID:101027907)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-02 03:06 PM . Last Modified: 2024-04-09 03:58 AM
Hi Steve , Any update about this ? Customer said that our encryption kit of TLS/SSL RC4 expose the vulnerability , They hope can disable RC4 encryption kit of TLS/SSL server . Does our new version of DCE can fix this issue ? Best Regards
(CID:102924906)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-02 03:07 PM . Last Modified: 2024-04-09 03:58 AM
Hi Chu, Sorry but I'm still awaiting a resolution. From what I've seen, they have scanned and come up with the same results. There is no new version in the immediate future that will resolve this to my knowledge but I have asked (just in seeing your note) if this can be done manually. If it can, this would require an APC person either remotely accessing the server or going on-site to potentially edit some back end files. I am not 100% sure this is an option but I am awaiting a response. Steve
(CID:102924964)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-02 03:07 PM . Last Modified: 2024-04-09 03:58 AM
Hi Steve , Any update about this issue ? I'm from Schneider Taiwan PEC team , If it can be done manually , I can go no site to solve this issue but need your help to send me like fix patch ... , thanks . Best Regards
(CID:104174375)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-02 03:07 PM . Last Modified: 2023-10-31 10:24 PM
This question is closed for comments. You're welcome to start a new topic if you have further comments on this issue.
Link copied. Please paste this link to share this article on your social media post.
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.