EcoStruxure IT forum
Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 08:18 PM . Last Modified: 2024-04-03 01:16 AM
Hi,
a customer has reported the following vulnerabilities in DCE 7.6:
Open SSH out of date:
CVE-2016-8858
CVE-2016-10010
CVE-2015-6563
CVE-2016-10012
CVE-2016-10009
CVE-2015-5600
CVE-2016-10011
CVE-2015-6564
Apache HTPP out of date:
CVE-2007-6750
OpenSSH out of date:
CVE-2018-15473
CVE-2016-0778
CVE-2016-0777
SSLv3:
CVE-2014-3566
SSL/TLS supporting TLSv1.0
QIDs 38628
OPEN SSH Users enumeration:
CVE-2018-15473
How can we update DCE server components?
Thanks
Antonio
(CID:146276902)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 08:18 PM . Last Modified: 2024-04-03 01:16 AM
I believe we will have to wait for a new version of the appliance. DCE 7.7 does not seem to address these: https://sxwhelpcenter.ecostruxureit.com/display/public/UADCE725/StruxureWare+Data+Center+Expert+v7.7...
(CID:146276910)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 08:18 PM . Last Modified: 2024-04-03 01:16 AM
Hi Antonio,
I haven't gone through each one individually. Most of these vulnerabilities you have listed are for SSH. SSH is only used when working with tech support and there is no access required by customers. SSH can be turned off.
I looked at the Apache vulnerability:
https://nvd.nist.gov/vuln/detail/CVE-2007-6750
It states:
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
I checked on DCE 7.6 and found that we are using version:
Server version: Apache/2.2.15 (Unix)
Server built: Jun 19 2018 15:45:13
7.7 uses the same version.
As for TLS versions and SSLv3, these are used for backwards compatibility to communicate with some older devices but can be turned off:
As for updating individual modules, you can't. We don't provide root access. Even if we did, upgrading to an untested version could cause unexpected issues.
I'll still forward your concerns but since these are mostly 2016 or earlier, I'm going to assume they are not being considered vital. I will let you know what more I hear, if anything.
Thanks,
Steve
(CID:146276970)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 08:18 PM . Last Modified: 2023-10-22 04:15 AM
This question is closed for comments. You're welcome to start a new topic if you have further comments on this issue.
Link copied. Please paste this link to share this article on your social media post.
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.