Dell Data Domain False Positive Security Vulnerabilities for DDOS 7.9.0.0

Summary: This article provides a list of security vulnerabilities which may be identified by security scanners.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Security Article Type

Security KB

CVE Identifier

The CVE IDs are listed in the table below.

Issue Summary

This article provides a list of security vulnerabilities that cannot be exploited on Dell Data Domain DDOS Release 7.9.0.0 and later but which may be identified by security scanners.

Details

Third-party Component CVE IDs Summary of Vulnerability Reason why Product is not Vulnerable Date Determined False Positive
RPC Qualys ID 66043 YP/NIS MOUNT RPC Services Listening on Non-Privileged Ports It is standard NFS practice to use port 2052, and it is the default mountd-port. If required, the mountd-port can be changed by user with the "nfs option. This requires corresponding changes on all clients.

A vulnerability exists in open Linux systems in using port 2052 for YP/NIS and MOUNT RPC Services. The DD system is a closed appliance with no defined access to load or run additional software not in DD OS. Root or BASH access is limited to DD Support staff working with local staff. DD administrators and users have no access to the protected file system, and are unable to install executable files. No malicious software can be added to DD system, mitigating any risk on port 2052 to run unauthorized services.
July 20, 2018
SNMP  Qualys ID 78030
CVE-1999-0517
CVE-1999-0516
Readable SNMP Information DD provides the ability to set SNMP V3 community string and does not allow the default.
See DD security configuration guide and admin guide for how to harden the system.
January 1, 2019
TLS/SSL Qualys ID 38169
Nessus ID 51192
SSL Certificate - Self-Signed Certificate Self-signed certificate is used by default until customer import certificate.
See DD security configuration guide and admin guide for how to harden the system.
March 3, 2019
TLS/SSL Qualys ID 38170 SSL Certificate - Subject Common Name Does not Match Server FQDN Self-signed certificate is used by default until customer import certificate.
See DD security configuration guide and admin guide for how to harden the system.
March 3, 2019
TLS/SSL Qualys ID 38173 SSL Certificate - Signature Verification Failed Vulnerability Self-signed certificate is used by default until customer import certificate.
See to DD security configuration guide and admin guide for how to harden the system.
March 3, 2019
OPENSSH Qualys ID 38772
CVE-2019-16905
OpenSSH Integer overflow Vulnerability DD does not compile OpenSSH using WITH_XMSS which is an experimental key type. May 15, 2020
Windows Qualys ID 90043 SMB Signing Disabled or SMB Signing Not Required SMB signing is disabled by default for performance reason.
See DD security configuration guide and admin guide for instructions how to enable SMB signing.
June 1, 2020
RPC Qualys ID 11 Hidden RPC services RPC Portmapper service is needed by DDOS functionality and cannot be turned off. RPC portmapper on tcp/udp 111 cannot be changed as a standard in RPC. DDOS does not have any vulnerability that is related to RPC services used.
If this is still a concern, customer can have two options to limit exposure of RPC portmapper service:
1) Configure DD to limit any portmapper query to DD by only known clients. See user guide for details.
or
2) If DD is located behind a customer's router/firewall, customer can configure the inbound firewall Access-control-list to limit any portmapper query (tcp/udp 111) to DD by only known clients or subnet.
June 20, 2021
NFS Acunetix
CVE-1999-055
NFS Exported Share Information Disclosure The remote NFS server is exporting one or more shares without restricting access (based on hostname, IP, or IP range). The remote NFS server exports world-readable shares.
See Dell KB article 3567 on configuration to avoid this false finding: EMC Data Domain 2500 Security Vulnerability for Missing Access Restrictions on exported NFS shares (CVE-1999-0554) - False Positive
February 21, 2021

Affected Products

Data Domain
Article Properties
Article Number: 000200174
Article Type: Security KB
Last Modified: 29 Jul 2022
Version:  1
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.