Unsolved
1 Rookie
•
1 Message
0
788
May 24th, 2023 01:00
OpenSSH vulnerability
Hi,
Our customer has switches N2024 and N1548 running versions N2000Stdv6.7.1.9 and N1500v6.7.1.9
He got a report from a penetration tester to change the version of the OpenSSH from OpenSSH 8.0 to 9.3
As I checked in the release notes Dell EMC Networking 6.7.1.21 / 6.7.1.51 Firmware Release Notes in these versions OpenSSH patches will applied.
If we upgrade the switches to versions N2000Stdv6.7.1.21 and N1500v6.7.1.21 it will solve the vulnerability ?
Thank you.
No Events found!
DELL-Chris H
Moderator
•
9.4K Posts
0
May 24th, 2023 05:00
Christoforos.v,
It does appear that the 6.7.1.21 version does include the OpenSSH vulnerability fix, so I would suggest updating and then retesting. If the vulnerability is different than the one addressed in the update, you may want to call in for assistance. The reason being is there does appear to be a workaround if the update fails to resolve, but it is lengthy and may require direct access.
Let me know if this helps.