Unsolved

1 Rookie

 • 

49 Posts

5

November 4th, 2025 13:46

Tenable Nessus Plugin 257438: Server 2016 vs Dell/EMC iDRAC Service Module < 6.0.3.0 Multiple Vulnerabilities (DSA-2025-311)

Servers running OS Server 2016 will always reflect a critical scan:

 * Apparently all versions Dell/EMC iSM < v6.0.3.0 are vulnerable to DSA-2026-311 / CVE-2025-38742

 * Dell/EMC doesn't support ISM version later than v3.3.1-1341_A00 on OS Server 2016

 * Tenable Nessus doesn't know about Dell/EMC internal release engineering plans, and blindly reports a critical vulnerability

Any suggestions, other than setting up a Nessus Plugin policy to ignore plugin 257438 / DSA-2026-311 / CVE-2025-38742?

It would be best of Dell/EMC could release a newer patch version of iSM v3.x (v3.3.2.x) ;  then the tenable nessus plugin could be updated with REGEXP for version strings.

Alternatively, any advice to force the v6.x MSI to install on Server 2016?

No Responses!
No Events found!

Top