Key Manager Appliance - iDRAC 6 v2.90 - Multiple Weak Encryption Ciphers Enabled
Originally Published: 2018-04-12
Article Number
Applies To
CVE Identifier(s)
Article Summary
CVE-2015-4000 - The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
CVE-2016-2183 - The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
Link to Advisories
https://nvd.nist.gov/vuln/detail/CVE-2015-4000 - Man-in-the-middle attacks by rewriting a ClientHello - aka "Logjam"
https://nvd.nist.gov/vuln/detail/CVE-2016-2183 - Obtain cleartext data via a birthday attack against a long-duration encrypted session - aka "Sweet32"
Alert Impact
Impacted - Apply Vendor Remedy
Alert Impact Explanation
Resolution
https://www.dell.com/support/home/us/en/19/Drivers/DriversDetails?driverId=8GMF6
Install and follow Dell's documented steps at:
http://en.community.dell.com/techcenter/b/techcenter/archive/2017/08/01/capability-for-disabling-tls1-0-on-idrac6-in-11th-generation-of-poweredge-servers.
Notes
https://www.dell.com/support/home/us/en/19/Drivers/DriversDetails?driverId=9GJYW
Disclaimer
Related Articles
Disabling weak ciphers using port 1813 in RSA Authentication Manager 8.3 patch 1 253Number of Views BIOS hardening for RSA Authentication Manager 8.x 277Number of Views SA: puppet agent -t shows rabbitmq permission issues post upgrade or installation of packages. 36Number of Views FIM - Encryption Algorithms Q&A 27Number of Views Installer prerequisite fails on files that are not relevant to the RSA Governance & Lifecycle deployment 144Number of Views
Trending Articles
RSA MFA Agent 2.4.3 for Microsoft Windows Group Policy Object Template Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA MFA Agent 2.4.3 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Deploying RSA Authenticator 6.2.2 for Windows Using DISM
Don't see what you're looking for?