Dell Data Domain False Positive Security Vulnerabilities for DDOS 7.9.0.0
Summary: This article provides a list of security vulnerabilities which may be identified by security scanners.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Security Article Type
Security KB
CVE Identifier
The CVE IDs are listed in the table below.
Issue Summary
This article provides a list of security vulnerabilities that cannot be exploited on Dell Data Domain DDOS Release 7.9.0.0 and later but which may be identified by security scanners.
Details
| Third-party Component | CVE IDs | Summary of Vulnerability | Reason why Product is not Vulnerable | Date Determined False Positive |
| RPC | Qualys ID 66043 | YP/NIS MOUNT RPC Services Listening on Non-Privileged Ports | It is standard NFS practice to use port 2052, and it is the default mountd-port. If required, the mountd-port can be changed by user with the "nfs option. This requires corresponding changes on all clients. A vulnerability exists in open Linux systems in using port 2052 for YP/NIS and MOUNT RPC Services. The DD system is a closed appliance with no defined access to load or run additional software not in DD OS. Root or BASH access is limited to DD Support staff working with local staff. DD administrators and users have no access to the protected file system, and are unable to install executable files. No malicious software can be added to DD system, mitigating any risk on port 2052 to run unauthorized services. |
July 20, 2018 |
| SNMP | Qualys ID 78030 CVE-1999-0517 CVE-1999-0516 |
Readable SNMP Information | DD provides the ability to set SNMP V3 community string and does not allow the default. See DD security configuration guide and admin guide for how to harden the system. |
January 1, 2019 |
| TLS/SSL | Qualys ID 38169 Nessus ID 51192 |
SSL Certificate - Self-Signed Certificate | Self-signed certificate is used by default until customer import certificate. See DD security configuration guide and admin guide for how to harden the system. |
March 3, 2019 |
| TLS/SSL | Qualys ID 38170 | SSL Certificate - Subject Common Name Does not Match Server FQDN | Self-signed certificate is used by default until customer import certificate. See DD security configuration guide and admin guide for how to harden the system. |
March 3, 2019 |
| TLS/SSL | Qualys ID 38173 | SSL Certificate - Signature Verification Failed Vulnerability | Self-signed certificate is used by default until customer import certificate. See to DD security configuration guide and admin guide for how to harden the system. |
March 3, 2019 |
| OPENSSH | Qualys ID 38772 CVE-2019-16905 |
OpenSSH Integer overflow Vulnerability | DD does not compile OpenSSH using WITH_XMSS which is an experimental key type. | May 15, 2020 |
| Windows | Qualys ID 90043 | SMB Signing Disabled or SMB Signing Not Required | SMB signing is disabled by default for performance reason. See DD security configuration guide and admin guide for instructions how to enable SMB signing. |
June 1, 2020 |
| RPC | Qualys ID 11 | Hidden RPC services | RPC Portmapper service is needed by DDOS functionality and cannot be turned off. RPC portmapper on tcp/udp 111 cannot be changed as a standard in RPC. DDOS does not have any vulnerability that is related to RPC services used. If this is still a concern, customer can have two options to limit exposure of RPC portmapper service: 1) Configure DD to limit any portmapper query to DD by only known clients. See user guide for details. or 2) If DD is located behind a customer's router/firewall, customer can configure the inbound firewall Access-control-list to limit any portmapper query (tcp/udp 111) to DD by only known clients or subnet. |
June 20, 2021 |
| NFS | Acunetix CVE-1999-055 |
NFS Exported Share Information Disclosure | The remote NFS server is exporting one or more shares without restricting access (based on hostname, IP, or IP range). The remote NFS server exports world-readable shares. See Dell KB article 3567 on configuration to avoid this false finding: EMC Data Domain 2500 Security Vulnerability for Missing Access Restrictions on exported NFS shares (CVE-1999-0554) - False Positive. |
February 21, 2021 |
Legal Disclaimer
Affected Products
Data DomainArticle Properties
Article Number: 000200174
Article Type: Security KB
Last Modified: 29 Jul 2022
Version: 1
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.