EcoStruxure IT forum
Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 10:47 PM . Last Modified: 2024-04-04 02:46 AM
Hi Team,
Customer ran a vulnerability scan on his network and did find the following on DCE & DCO, it all has to do with a update of OpenSSH to a version 7.7p1 or later.
DCE = 7.5 & DCO = 8.2.2
In which version of DCE/DCO will this be updated ?
(CID:134026904)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 10:47 PM . Last Modified: 2024-04-04 02:46 AM
Hi Cees,
. The current suggestion I can make and what we’re asked to do for customer is to note:
And that
Thanks,
Steve
(CID:134027416)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 10:47 PM . Last Modified: 2024-04-04 02:46 AM
...Very interesting, but even the most recent official updates for RHEL-7.5 (and for CentOS-7.5) offer a vulnerable version of OpenSSH:
$ uname -a
Linux 3.10.0-862.11.6.el7.x86_64 #1 SMP Fri Aug 10 16:55:11 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
$ rpm -qa | grep ssh
openssh-server-7.4p1-16.el7.x86_64
openssh-7.4p1-16.el7.x86_64
openssh-clients-7.4p1-16.el7.x86_64
libssh2-1.4.3-10.el7_2.1.x86_64
(CID:134027175)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 10:47 PM . Last Modified: 2024-04-04 02:46 AM
hmm, interesting ...
(CID:134027218)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 10:47 PM . Last Modified: 2024-04-04 02:46 AM
Hi Cees,
. The current suggestion I can make and what we’re asked to do for customer is to note:
And that
Thanks,
Steve
(CID:134027416)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 10:47 PM . Last Modified: 2024-04-04 02:46 AM
Thanks Steve, I will contact the customer to sent their vulnerability report to the email address mentioned above.
Regards,
Cees
(CID:134027427)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 10:48 PM . Last Modified: 2024-04-04 02:46 AM
Hi Cees,
Here is a brief summary of our responses to the vulnerabilities highlighted within the underlying packages installed on DCE 7.5. A follow on post will do the same for DCO.
CVE-2016-1908 and CVE-2015-5600 are both addressed within DCE 7.5 as it uses a newer version of openssh (openssh-5.3p1-123.el6_9.x86_64), which contains fixes for both.
The other 3 issues are not technically fixed in our shipping version of openssh, as fixes are not available on CentOS 6, but they are generally not exploitable and/or can be mitigated by a user. Details below on that below:
It's worth noting that fixes are available for these issues within CentOS 7. DCE will move to this version in a future release, likely within 2019.
Please let me know if you or your customer have any follow on questions or concerns and we'd be happy to answer them.
Thanks,
Brian Behbehani
(CID:134028283)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 10:48 PM . Last Modified: 2024-04-04 02:46 AM
Hi Brian,
Thanks a lot for your clear answer, will sent this info to the customer.
Will wait for the response on DCO,
Best regards,
Cees
(CID:134028503)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 10:48 PM . Last Modified: 2024-04-04 02:46 AM
Hi Cees
As Brian Behbehani mentioned fixes are available for these issues within CentOS 7, Data Center Operations 8.2.2 is shipped with CentOS 7.4 and openssh packages that are installed contain fixes for mentioned vulnerabilities.
OpenSSH packages that are installed with Data Center Operations 8.2.2 are
openssh-server-7.4p1-13.el7_4.x86_64
openssh-7.4p1-13.el7_4.x86_64
openssh-clients-7.4p1-13.el7_4.x86_64
Please see here for updated packages that contain vulnerability fixes https://access.redhat.com/errata/RHSA-2017:2029
You are more than welcome to contact us if you have any follow up questions.
Regards
Elvedin
(CID:134028629)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 10:48 PM . Last Modified: 2024-04-04 02:46 AM
Hi Elvedin, thanks a lot for your response,
Best regards,
Cees
(CID:134028632)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-04 10:48 PM . Last Modified: 2023-10-22 04:16 AM
This question is closed for comments. You're welcome to start a new topic if you have further comments on this issue.
Link copied. Please paste this link to share this article on your social media post.
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.