Key Manager Appliance - iDRAC 6 v2.90 - Multiple Weak Encryption Ciphers Enabled
Originally Published: 2018-04-12
Article Number
Applies To
CVE Identifier(s)
Article Summary
CVE-2015-4000 - The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
CVE-2016-2183 - The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
Link to Advisories
https://nvd.nist.gov/vuln/detail/CVE-2015-4000 - Man-in-the-middle attacks by rewriting a ClientHello - aka "Logjam"
https://nvd.nist.gov/vuln/detail/CVE-2016-2183 - Obtain cleartext data via a birthday attack against a long-duration encrypted session - aka "Sweet32"
Alert Impact
Impacted - Apply Vendor Remedy
Alert Impact Explanation
Resolution
https://www.dell.com/support/home/us/en/19/Drivers/DriversDetails?driverId=8GMF6
Install and follow Dell's documented steps at:
http://en.community.dell.com/techcenter/b/techcenter/archive/2017/08/01/capability-for-disabling-tls1-0-on-idrac6-in-11th-generation-of-poweredge-servers.
Notes
https://www.dell.com/support/home/us/en/19/Drivers/DriversDetails?driverId=9GJYW
Disclaimer
Related Articles
RSA Governance & Lifecycle Data Processors: Setting is Disabled flag in REST account collectors 25Number of Views Unable to set credentials or configure RSA SecurID Appliance 350 iDRAC configuration 206Number of Views Failed to install manual node secret in RSA Authentication Manager 8.4 187Number of Views Disabling weak ciphers using port 1813 in RSA Authentication Manager 8.3 patch 1 274Number of Views RSA Authentication Manager Availability of Firmware Updates to Address iDRAC Vulnerabilities 63Number of Views
Trending Articles
RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide How to Download OTP Token Seed Files from myRSA RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide Module "SecurIDModule" could not be found message displayed in the web browser
Don't see what you're looking for?