VMware Cloud Community
SCliu
Contributor
Contributor

ESXi 5.5.0U3 CVE-2011-1473 issue

I have an ESXi 5.5 server with serveral hosts.

The version is ESXi-5.5.0-9919047.

Recently our IT security auditor report that the server is subject to the "The remote service allows repeated renegotiation of TLS / SSL connections." problem.

The CVE number is CVE-2011-1473.

How can I fix this problem?

Reply
0 Kudos
7 Replies
daphnissov
Immortal
Immortal

You can upgrade ESXi which is quite old at this point and no longer even supported.

Reply
0 Kudos
SCliu
Contributor
Contributor

Thanks.

The HP DL580G7 server does not support the latest ESXI6.7. Worried that the system is unstable after the upgrade. So I want to fix the patch.

Reply
0 Kudos
a_p_
Leadership
Leadership

The server model supports ESXi 6.0 with the latest patches, so that may be an option to patch what you mentioned as well as several other issues.

I'd recommend that you also update the host's firmware to the latest available G7-SPP unless already done.

André

Reply
0 Kudos
daphnissov
Immortal
Immortal

I wasn't suggesting 6.7 necessarily, but those old Gen 7 boxes support 6.0. Note that even if you upgrade, it may still not be resolved. See: VMware Knowledge Base

Reply
0 Kudos
SCliu
Contributor
Contributor

Thank you very much for your professional answer.

This problem is really a headache. The hardware does not support upgrading to ESX6.7. Upgrading to 6.0 does not solve the problem.

Thanks also to everyone, let me have a correct understanding of this issue.

Reply
0 Kudos
daphnissov
Immortal
Immortal

Let me also just state for the record:  In order to keep current with patches which often bring security fixes (not to mention stability and performance fixes), it's necessary to keep your hardware somewhat current. Expecting that vendors will continue to bring support, including modern security patches, to eight-year-old hardware is just not reasonable and isn't how technology works. So while upgrading hardware may not necessarily remediate this one specific CVE, it will assist in ensuring you are able to get them in the future.

Reply
0 Kudos
SCliu
Contributor
Contributor

I understand your suggestion. A new hardware platform has been built and the application has been migrated. The old equipment (HP DL580 and IBM V7000) was transformed into a test platform. During the transformation process, it was found that the latest patch of ESXI5.5 was completed and only one vulnerability (CVE-2011-1473) was reported. I want to use your help to get a safety assessment score below 2.0, which is very safe. At present, this desire cannot be realized.

thank you very much.

Reply
0 Kudos