DSA-2024-025: Security Update for Dell InsightIQ for OpenSSH Vulnerability

Summary: Dell InsightIQ remediation is available for openSSH vulnerability that could be exploited by malicious users to compromise the affected system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Medium

Details

Third-Party Component CVE More information
openSSH CVE-2023-48795 https://nvd.nist.gov/vuln/detail/CVE-2023-48795 This hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product Affected Versions Remediated Versions Link
InsightIQ Versions 4.2 through 4.4.1 None See Workarounds and Mitigations section.
InsightIQ 5.0 5.1 PowerScale InsightIQ Drivers & Downloads
Product Affected Versions Remediated Versions Link
InsightIQ Versions 4.2 through 4.4.1 None See Workarounds and Mitigations section.
InsightIQ 5.0 5.1 PowerScale InsightIQ Drivers & Downloads

Workarounds & Mitigations

CVE ID Workaround and Mitigation
CVE-2023-48795 For CentOS 7.9 (or RHEL 7):
Step 1: Please login to IIQ 4.x OVA system using ssh
Step 2: Please take backup of original ssh_config and sshd_config files to a different location.
Step 3: We recommend using strict MACs and Ciphers on CentOS 7.9 (or RHEL 7) in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config.
Step 4: Below strict set of Ciphers and MACs can be used as mitigation:
Ciphers:
  • aes128-ctr
  • aes192-ctr
  • aes256-ctr
  • aes128-gcm@openssh.com
  • aes256-gcm@openssh.com
MACs:
  • umac-64@openssh.com
  • umac-128@openssh.com
  • hmac-sha2-256
  • hmac-sha2-512
  1. Open/etc/ssh/ssh_config and/etc/ssh/sshd_config files using any preferred editor
  2. Add or modify the above mentioned Ciphers and MACs in above mentioned two files
  3. Please remove the Ciphers and MACs which are not mentioned above
  4. If the mentioned Ciphers and MACs are already present, then no action required
Note: If configured improperly or your ssh client does not support these algorithms, you may lose access to your server

OR
 
  1. Open /etc/ssh/ssh_config and /etc/ssh/sshd_config files using any preferred editor
  2. Please remove the chacha20-poly1305@openssh.com cipher and etm MACs from the above mentioned two files
  3. If the mentioned Ciphers and MACs are already removed, then no action required
Note: If configured improperly or your ssh client does not support these algorithms, you may lose access to your server

Step 5: Please note that the restart of sshd service may terminate the existing ssh connections to IIQ 4.x OVA system.
  1. Restart sshd service using following command: # systemctl restart sshd
  2. Next, please (re)connect to IIQ 4.x OVA system using ssh
Step 6: Please check sshd service status using following command: # systemctl status sshd
  • # ssh -Q cipher
  • # ssh -Q mac
  • # sshd -T | grep -e '^ciphers ' -e '^macs '
  • If not, please repeat step 4.
Step 7: Please verify only the needed Ciphers and MACs (as mentioned in step 4) have been updated using the following commands on IIQ 4.x OVA system.
Step 8: Done.

Revision History

RevisionDateDescription
1.02024-01-12Initial Release
2.02024-05-30Updated Affected Products and Remediation: Expected Release Date for InsightIQ v.5.1
3.02024-07-01Updated Affected Products and Remediation: Update Link

Related Information

Affected Products

Isilon InsightIQ, PowerScale InsightIQ
Article Properties
Article Number: 000222001
Article Type: Dell Security Advisory
Last Modified: 01 Jul 2024
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.