Skip to main content

Hitachi

Server and Client Products Vulnerability Information

Overview

Server and Client products has vulnerability in Network Time Protocol daemon (ntpd)

1. Product

Correspond Vulnerability Effect Reason/Action
CVE
-2014
-9293
CVE
-2014
-9294
CVE
-2014
-9295
CVE
-2014
-9296
Enterprise Server AP7000 Not
Correspond
Not
Correspond
Correspond Not
Correspond
Not
Affected
Only when starting, the port of the object is temporarily opened.
After that, there is not affected because it is inaccessible.
Enterprise Server AP8800 [CSC] Not Correspond Not
Correspond
Correspond Not Correspond Not Affected All packets except the registered NTP server are disregarded.
There is not affected because the registered NTP server also specifies“noquery”
BladeSymphony
BS2500
CB2500
[BMC] Not Correspond Not
Correspond
Not
Correspond
Not Correspond Not Affected
[SVP] Not Correspond Not
Correspond
Correspond Not Correspond Not Affected All packets except the registered NTP server are disregarded.
There is not affected because the registered NTP server also specifies“noquery”
[LANSW] Not
Correspond
Not
Correspond
Not
Correspond
Not Correspond Not
Affected
[DCBSW] Not Correspond Not
Correspond
Not Correspond Not Correspond Not Affected
[Virtage] Not Correspond Not
Correspond
Not Correspond Not Correspond Not Affected
BladeSymphony
BS2000
CB2000
[BMC] Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
[SVP] Not Correspond Not Correspond Correspond Not Correspond Not Affected All packets except the registered NTP server are disregarded.
There is not affected because the registered NTP server also specifies“noquery”
[LANSW] Correspond Not Correspond Correspond Not Correspond Affected There is not affected when "ntp" is not used.
The measures version (Ver.11.6.E) had released in November.
[DCBSW] Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
[FCSW] Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
[Virtage] Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
BladeSymphony
BS1000
[BMC] Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
[SVP] Not Correspond Not Correspond Correspond Not Correspond Not Affected All packets except the registered NTP server are disregarded.
There is not affected because the registered NTP server also specifies“noquery”
[LANSW] Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
[FCSW] Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
[Virtage] Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
BladeSymphony
BS500
CB500
[BMC] Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
[SVP] Not Correspond Not Correspond Correspond Not Correspond Not Affected All packets except the registered NTP server are disregarded.
There is not affected because the registered NTP server also specifies“noquery”
[LANSW] Correspond Not Correspond Correspond Not Correspond Affected There is not affected when "ntp" is not used.
The measures version (Ver.11.6.E) had released in November.
[DCBSW] Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
[FCSW] Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
[Virtage] Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
BladeSymphony
BS320
CB320
[BMC] Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
[SVP] Not Correspond Not Correspond Correspond Not Correspond Not Affected All packets except the registered NTP server are disregarded.
There is not affected because the registered NTP server also specifies“noquery”
[LANSW] Correspond Not Correspond Correspond Not Correspond Affected There is not affected when "ntp" is not used.
The measures version (Ver.11.6.E) had released in November.
[Virtage] Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
Hitachi Advanced Server
HA8000CR
RS440xM Correspond Correspond Correspond Correspond Not Affected There is not affected because it does not use it for the time synchronization.
Other than RS440xM Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
Entry Blade Server
HA8000-bd
Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
Client Blade FLORA
bd100/bd500
Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
Thin Client FLORA
Se210/Se330
Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
Entry Class Disk Array
BR1200
Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
Uninterruptible Power-supply System (UPS) Management Software,
Option PowerChute Business Edition,
PowerChute Network Shutdown,
PowerMonitor H,
PowerMonitor H for Network,
Network Management Card,
SNMP Card
Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
Display/Keyboard Unit,
Console Switching Unit
Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
Load Balancer
AX2000/AX2000HL/AX2500
Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
Load Balancer
BIG-IP1500
Not Correspond Not Correspond Correspond Not Correspond Not Affected It is protected by manager's user-name and password.
Hitachi Server Navigator Update Manager/Log Collect,
Log Monitor,
Log Monitor Logger,
Alive Monitor,
RAID Navigator
Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
Hitachi Server Navigator Installation Assistant Not Correspond Not Correspond Not Correspond Not Correspond Not Affected
Hitachi bd Link Not Correspond Not Correspond Not Correspond Not Correspond Not Affected

2. Avoidance

Please intercept the management network from an external network The offer of the measures version is updated later in this home page.

3. Solution

Please contact the product support and get the measures version for firmware.

4.Change History

December 21, 2015 : The BladeSymphony [LANSW] information was updated., sent.

October 16, 2015 : The BladeSymphony [LANSW] information was updated., sent.

March 13, 2015 : This security information page is made newly, sent.