Summary:
Dell EMC identified vulnerabilities in the iDRAC (Integrated Dell Remote Access Controller) management platform on Dell PowerEdge servers, including three used as platforms for the RSA Authentication Manager hardware appliance.
Dell EMC iDRAC response to multiple CVE's June 2018
(Dell EMC Whitepaper)
http://en.community.dell.com/techcenter/extras/m/white_papers/20487494
Affected Products:
- RSA SecurID Hardware Appliance Model 130 based on the Dell PowerEdge R230
- RSA SecurID Hardware Appliance Model 250 based on the Dell PowerEdge R630
- RSA SecurID Hardware Appliance Model 250 based on the Dell PowerEdge R710
Note: To determine your hardware platform, see the following Knowledgebase article:
000036316 - How to determine the RSA Authentication Manager 8.x hardware platform
Recommendation:
RSA recommends that customers using the Dell PowerEdge R230 and Dell PowerEdge R630 hardware platform apply the firmware patch for iDRAC8.
RSA recommends that customers using the Dell PowerEdge R710 hardware platform apply the firmware patch for iDRAC6.
Dell EMC iDRAC7/iDRAC8 version 2.60.60.60
Download the Windows self-extracting executable version of the patch from
https://downloads.dell.com/FOLDER05025737M/1/
Dell EMC iDRAC6 version 2.91 for Monolithic servers
Download the Windows self-extracting executable version of the patch from
https://downloads.dell.com/FOLDER05060172M/1/
Important: Please use the following instructions for updating the iDRAC firmware:
EOPS Policy:
RSA has a defined End of Primary Support policy associated with all major versions. Please refer to the Product Version Life Cycle for additional details.
Related Articles
DSA-2020-098: RSA Identity Governance and Lifecycle Security Update for Dell EMC iDRAC Vulnerability 7Number of Views nCipher firmware upgrade does not use the environment variables for change of default ports. 5Number of Views DSA-2019-068: RSA Authentication Manager Security Update for Multiple Hardware Appliance Firmware Vulnerabilities 34Number of Views How to determine which firmware version is on an RSA SecurID SID800 authenticator 31Number of Views Compliance: change default password for log-hybrid sftp/upload accounts 30Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide