IBM Support

Security Bulletin: Vulnerability in Intel Ethernet Controller XL710 affects IBM MQ Appliance

Security Bulletin


Summary

A vulnerability in the Intel Ethernet Controller XL710 affects IBM MQ Appliance M2001.

Vulnerability Details

CVEID: CVE-2016-8106
DESCRIPTION: Intel Ethernet Controller X710/XL710 is vulnerable to a denial of service, caused by improper handling of certain network traffic. By sending specially-crafted network traffic, a remote attacker could exploit this vulnerability to cause the system to stop responding.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/120415 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

IBM MQ Appliance

  • M2001 appliance with serial numbers in the range 7802314 to 7803646, independent of IBM MQ Appliance firmware version.

Remediation/Fixes

Use the Platform Hardware Diagnostics NVM Tool v1.1.1.3 to upgrade the Intel Ethernet Control XL710 to NVM 5.05.

**** Update January 2018: ****
The previously available NVM Tool, dated 20170329-1238, could fail to upgrade the Intel Ethernet Control XL710 to NVM 5.05.

If you used that version of the NVM Tool, you must re-apply the fix using the NVM Tool dated 20170906-0927, which is the version now linked from this document.

The tool reports the current firmware version before upgrading. If the firmware has already been successfully upgraded, the following message is displayed:

  • All 10/40G NIC firmware are up-to-date. Aborting.

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Change History

04 Jan 2018 Update for NVM tool
30 Jun 2017 Original version published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Internal Use Only

Advisory ID    8397
Product Record ID    93984

[{"Product":{"code":"SS5K6E","label":"IBM MQ Appliance"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"--","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"9.0.4;9.0.3;9.0.2;9.0.1;8.0","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
13 August 2019

UID

swg22002763