DCO DR 8.2.7 vulnerability - General remote services
EcoStruxure IT forum
Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send InviteCancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-12-0901:13 AM
DCO DR 8.2.7 vulnerability - General remote services
HI,
One of our client found the vulnerability on DCO DR version 8.2.7 which is mentioned as below:
38142
SSL Server Allows Anonymous Authentication Vulnerability
4
Active
5432
General remote services
5.1
Disable support for anonymous authentication to mitigate this vulnerability.
Tried upgrading the version to 8.3 but it failed. Even the fresh installation would need lots of approval from customer side which would take more month. right now, customer wanted to resolve this in quick. In the mean-time, do we have any solution to remediate this vulnerability for 8.2.7 other than fresh installation? any suggestions please?
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-12-2209:57 AM
Hello
In regards to your post. The tools referenced by the CVE's in this post are not tools we typically include out of box with DCO 8.2.7. Were these tools added by your staff?