Unsolved
1 Rookie
•
49 Posts
0
5
November 4th, 2025 13:46
Tenable Nessus Plugin 257438: Server 2016 vs Dell/EMC iDRAC Service Module < 6.0.3.0 Multiple Vulnerabilities (DSA-2025-311)
Servers running OS Server 2016 will always reflect a critical scan:
* Apparently all versions Dell/EMC iSM < v6.0.3.0 are vulnerable to DSA-2026-311 / CVE-2025-38742
* Dell/EMC doesn't support ISM version later than v3.3.1-1341_A00 on OS Server 2016
* Tenable Nessus doesn't know about Dell/EMC internal release engineering plans, and blindly reports a critical vulnerability
Any suggestions, other than setting up a Nessus Plugin policy to ignore plugin 257438 / DSA-2026-311 / CVE-2025-38742?
It would be best of Dell/EMC could release a newer patch version of iSM v3.x (v3.3.2.x) ; then the tenable nessus plugin could be updated with REGEXP for version strings.
Alternatively, any advice to force the v6.x MSI to install on Server 2016?



