Key Manager Appliance - iDRAC 6 v2.90 - Multiple Weak Encryption Ciphers Enabled
Originally Published: 2018-04-12
Article Number
Applies To
CVE Identifier(s)
Article Summary
CVE-2015-4000 - The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
CVE-2016-2183 - The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
Link to Advisories
https://nvd.nist.gov/vuln/detail/CVE-2015-4000 - Man-in-the-middle attacks by rewriting a ClientHello - aka "Logjam"
https://nvd.nist.gov/vuln/detail/CVE-2016-2183 - Obtain cleartext data via a birthday attack against a long-duration encrypted session - aka "Sweet32"
Alert Impact
Impacted - Apply Vendor Remedy
Alert Impact Explanation
Resolution
https://www.dell.com/support/home/us/en/19/Drivers/DriversDetails?driverId=8GMF6
Install and follow Dell's documented steps at:
http://en.community.dell.com/techcenter/b/techcenter/archive/2017/08/01/capability-for-disabling-tls1-0-on-idrac6-in-11th-generation-of-poweredge-servers.
Notes
https://www.dell.com/support/home/us/en/19/Drivers/DriversDetails?driverId=9GJYW
Disclaimer
Related Articles
Error "No appropriate protocol" in RSA Access Manager 6.2 45Number of Views To generate FIPS compliant pkcs12 file using Openssl 39Number of Views Disabling weak ciphers using port 1813 in RSA Authentication Manager 8.3 patch 1 279Number of Views FIM - Encryption Algorithms Q&A 28Number of Views RSA Access Manager API cannot connect to 6.2 SP4 Servers due to SSLException illegal_parameter error 25Number of Views
Don't see what you're looking for?