Release Notes
Abstract
This firmware update (V5.0.0) provided by IBM updates QRadar® M7 appliances with updates for UEFI, XCC, RAID controllers, and HDD software fixes and enhancements. This firmware can be used on all QRadar M7 appliances, but requires that the administrator configures their XClarity Controller (XCC) for remote management.
Content
Important: Select a tab to read each step of the firmware procedure.
The M7 firmware v5.0.0 ISO is intended to remotely update software through the XClarity Controller (XCC) user interface. Administrators must extract the EXE file and apply the uxz file to update their XClarity Controller, then the ISO can be mounted to apply the remainder of the firmware updates. The installation instructions are provided on tab named 'Part 2. Installing Firmware Updates'. These instructions guide customers through a remote upgrade of their firmware. If you are local to your appliances or have issues with your XClarity configuration.
Limitation: Due to changes in the bundled software, a USB firmware update method is not available on IBM Fix Central at this time. Administrators must use the XCC method to update their M7 firmware.
Important: If your appliance is in a HA pair, there are configuration steps required to set the status properly for your primary and secondary high-availability appliances. For more information, see: http://www.ibm.com/support/docview.wss?uid=swg27047121#HA.
This firmware update applies to the following IBM Security QRadar M7 (1U and 2U form factor) appliance types:
Table 1: List of appliances the M7 appliance firmware V5.0.0 can update.
Part 1: About the M7 firmware V5.0.0 update
The M7 firmware v5.0.0 ISO is intended to remotely update software through the XClarity Controller (XCC) user interface. Administrators must extract the EXE file and apply the uxz file to update their XClarity Controller, then the ISO can be mounted to apply the remainder of the firmware updates. The installation instructions are provided on tab named 'Part 2. Installing Firmware Updates'. These instructions guide customers through a remote upgrade of their firmware. If you are local to your appliances or have issues with your XClarity configuration.
Limitation: Due to changes in the bundled software, a USB firmware update method is not available on IBM Fix Central at this time. Administrators must use the XCC method to update their M7 firmware.
Important: If your appliance is in a HA pair, there are configuration steps required to set the status properly for your primary and secondary high-availability appliances. For more information, see: http://www.ibm.com/support/docview.wss?uid=swg27047121#HA.
Supported appliances, types, and model information
This firmware update applies to the following IBM Security QRadar M7 (1U and 2U form factor) appliance types:
Hardware | Details |
Appliance and machine type model (MTM) |
1U
IBM QRadar Network Insights Appliance 1901 (MTM 4723-N9C) IBM QRadar XX05 1U (MTM 4723-Q7B)
IBM QRadar Event/QFlow Collector Appliance 1501/1201 1U (MTM 4723-Q9C)
IBM QRadar XX48 1U (MTM 4793-Q8D)
2U
IBM QRadar Network Insights 1920 2U (MTM 4723-N2A) IBM QRadar Network Insights 1940 2U (MTM 4723-N4B)
IBM QRadar XX29 M7 appliance 2U (4723-Q9A) IBM QRadar Incident Forensics Appliance 2U (MTM 4723-F1A)
IBM QRadar Network Packet Capture Appliance 2U (MTM 4723-P1A) For capabilities on these appliances, see QRadar M7 appliance overview. |
Server Type | M7 |
Server Machine Type | SR630 V2 (7Z71)/ M7 1U SR650 V2 (7Z73) / M7 2U |
Important information and prerequisites in this firmware update
Administrators must ensure that their M7 appliance includes the minimum version outlined in the Prerequisite version column. If your M7 appliance does not meet the prerequisite versions outlined in the table, the administrator must contact IBM QRadar Support to discuss a custom upgrade path for your M7 appliance.
Table 2: Firmware versions and any prerequisite for each component are provided in this table.
Component | Prerequisites | Firmware version in this update | File name |
UEFI/BIOS | None | afe128f-3.20 | lnvgy_fw_uefi_afe128f-3.20_anyos_32-64.uxz |
XCC | None | afot48b-4.70 | oem_fw_xcc_afot48b-4.70_anyos_noarch.uxz |
LXPM | None | xwl222d-3.25 xwl122b-3.25 |
lnvgy_fw_drvln_xwl222d-3.25_anyos_noarch.uxz lnvgy_fw_lxpm_xwl122b-3.25_anyos_noarch.uxz |
RAID controller
|
None | 940-52.27.0-5215-0 (940-8e) 940-52.27.0-5215-0 (940-16i) 540-52.27.0-5216-0 (540-8i) |
lnvgy_fw_raid_mr3.5.940-52.27.0-5215-0_linux_x86-64.bin lnvgy_fw_raid_mr3.5.940-52.27.0-5215-0_linux_x86-64.bin lnvgy_fw_raid_mr3.5.540-52.27.0-5216-0_linux_x86-64.bin |
NIC
|
None | 4.30-1.3518.0-2 9.30-6.20-1.3450.0-10 |
intc-lnvgy_fw_nic_net.e800.da2.pcie-4.30-1.3518.0-2_linux_x86-64.bin intc-lnvgy_fw_nic_net-9.30-6.20-1.3450.0-10_linux_x86-64.bin |
Emulex | None | 14.2.673.40-4 | elx-lnvgy_fw_fc_lp.35-14.2.673.40-4_linux_x86-64.bin |
HDD | None | 1.50.58-0 | lnvgy_fw_drives_all-1.50.58-0_linux_x86-64.bin |
NOTES
- A number of hard disk drives can be installed in this appliance. The HDD update tool examines the hard disk drives that are present and selects the latest firmware version that is available for your drive.
- The base system pack might contain other firmware packages that are not present in QRadar appliances. Firmware updates from the base system pack might be displayed with a status of "undetected" when the tool compares available firmware to the hardware in the appliance.
- For general firmware questions and information, see our FAQ page at http://ibm.biz/qradarfirmware.
Security issues resolved in this firmware update
The table lists the software versions and CVEs addressed in the firmware release.
Component | File name | Updates |
UEFI/BIOS | lnvgy_fw_uefi_afe128f-3.20_anyos_32-64.uxz |
Resolved CVEs
CVE-2023-22655, CVE-2023-23583, CVE-2023-22655, CVE-2023-35191, CVE-2023-45229, CVE-2023-45230, CVE-2023-45231, CVE-2023-45232, CVE- 2023-45233, CVE-2023-45234, CVE-2023-45235, CVE-2023-45236, CVE-2023-45237, and CVE-2023-23583. Security
Enhancements
Fixes
Limitations
|
XCC | oem_fw_xcc_afot48b-4.70_anyos_noarch.uxz |
Resolved CVEs
CVE-2023-51767, CVE-2023-51385, CVE-2023-51384, CVE-2023-48795, CVE-2023-38408, CVE-2023-28531, and CVE-2023-25136 |
LXPM | lnvgy_fw_drvln_xwl222d-3.25_anyos_noarch.uxz lnvgy_fw_lxpm_xwl122b-3.25_anyos_noarch.uxz |
None |
RAID controller | lnvgy_fw_raid_mr3.5.940-52.27.0-5215-0_linux_x86-64.bin lnvgy_fw_raid_mr3.5.940-52.27.0-5215-0_linux_x86-64.bin lnvgy_fw_raid_mr3.5.540-52.27.0-5216-0_linux_x86-64.bin |
None |
NIC | intc-lnvgy_fw_nic_net.e800.da2.pcie-4.30-1.3518.0-2_linux_x86-64.bin intc-lnvgy_fw_nic_net-9.30-6.20-1.3450.0-10_linux_x86-64.bin |
None |
Emulex | elx-lnvgy_fw_fc_lp.35-14.2.673.40-4_linux_x86-64.bin | None |
HDD | lnvgy_fw_drives_all-1.50.58-0_linux_x86-64.bin |
Fixes
Updates firmware for issues where users reported that drives can incorrectly display errors.
|
Table 3: Issues resolved in the M7 firmware update 5.0.0.
A. Before you begin
- This installation method uses the hardware's integrated XCC interface to remotely update firmware.
- If your appliances are in a HA pair, you must prepare your high-availability appliances by using the instructions found here: http://www.ibm.com/support/docview.wss?uid=swg27047121#HA .
- A number of hard disk drives can be installed in this appliance. The HDD update tool examines the hard disk drives that are present and selects the most current firmware level that is available.
B. Downloading and extracting the firmware update
- Download the QRadar M7 appliance firmware from IBM Fix Central: M7 firmware 5.0.0 EXE download.
- Copy the M7 appliance firmware EXE to a directory on the Windows host.
- Double-click the file Qradar_ISO_M7_1U_SR630V2_7Z71_2U_SR650V2_7Z73_5_0_0.exe.
- Select or type a directory path for the firmware update and click Extract.
- The following files are extracted:
C. Updating the XCC firmware
- Log in to the XClarity interface on your QRadar M7 appliance.
- From the navigation sidebar, click Firmware Update.
- Click Update Firmware.
- Click Browse and choose the XClarity (XCC) firmware update oem_fw_xcc_afot48b-4.70_anyos_noarch.uxz.
- Click Next to upload and verify the XCC firmware file.
- Select the BMC (Primary) check box and click Next.
Important: The backup firmware bank is automatically updated. Administrators must ensure the BMC (Backup) check box is cleared (not selected). Administrators who select both check boxes must reinstall their firmware to ensure the primary bank updates properly. - Wait for the update the primary firmware banks to complete.
- Click Restart BMC and clear your browser cache.
Results
Wait for 5 minutes for the XCC interface to restart and log in. Continue to the next section to mount the firmware ISO and configure the boot options.
D. Mounting the M7 Firmware ISO
- From the OEM Controller menu, click Remote Console.
- Click Remote Console Preview.
IMPORTANT: Confirm the following parameters:
2a. Launch the session in Single User Mode.
2b. Clear the Allow others to request my remote session disconnect check box.
2c. Click Launch Remote Console to connect to the appliance. - To boot to the QRadar firmware update package ISO, click Media to mount the ISO image.
- In the Mount Virtual Media window, click Activate.
- Click Browse to select Qradar_ISO_M7_1U_SR630V2_7Z71_2U_SR650V2_7Z73_5_0_0.iso.
- Click Mount all local media.
- Note: If successful, a checkmark appears next to the uploaded ISO file.
Click the X to close the Mount Virtual Media window. - Select Power > Restart Server Normally
- When the machine powers back on, press F12 to select F12: One Time Boot Device.
Note: The field F12: One Time Boot Device displays with a blue background to indicate the virtual keyboard is selected. - Optional. If the F12: One Time Boot Device field is not selected, launch the virtual keyboard to press the F12 key.
- From the Boot Devices Manager menu:
- In the Legacy Mode field, press the Space Bar to clear the value. Legacy Mode is selected by default and you must be clear the value before you continue.
- Select XCC Virtual Media and press Enter.
- The Lenovo XClarity Essentials UpdateXpress System Pack Installer is launched. This may take 15-20 minutes to boot.
- In the Target Server - Setting menu, verify that Input BMC access check boxes is cleared (not selected) and click Next.
-
In the Update Setting menu, verify that all check boxes are cleared (not selected) and click Next.
- From the Update Recommendation menu, click Begin.
- The Lenovo XClarity Essentials UpdateXpress System Pack Installer compares the current package with the installed firmware.
- Review the list of updates.
Important: In the next step, administrators must confirm that all recommended updates are CHECKED, except for Lenovo/XClarity Controller XCC as this firmware was updated manually by the administrator in previous steps. - Verify the check box for Lenovo/XClarity Controller (XCC) is clear (not selected) and click Next.
- Wait for the firmware updates to load.
- Click Begin Update to install the firmware.
- At the update confirmation dialogue window, click Yes to continue.
- Verify that all updates complete successfully and click Next.
- Click Close to exit.
- The appliance must reboot to complete the firmware installation.
- Click Media to open the Mount Virtual Media window, and click Unmount.
Results
After the ISO file is unmounted, the administrator can log out and complete this procedure on other QRadar appliances. If you experience any installation issues, you can contact QRadar Support for assistance and open a software support case for your appliance. The support representative can request the firmware logs for review to determine the root cause of the issue or if replacement hardware is required. If the issue is hardware-related, the support representative can change the case type and involve the proper teams to schedule replacement parts.
Troubleshooting
- A green screen is not indicative of failure by itself, press CTRL on your keyboard to wake up the screen saver. If CTRL does not wake up the screensaver, you might need to press ENTER key. After ENTER key is pressed, if the Green background screen remains, check the power state of the XCC by going to the OEM Controller home page to view the power status in the upper left screen.
Note: If you can't reconnect to the IMM, or XCC, you need to send someone to the site to check on the machine status. In some rare circumstances, IMM can disconnect and the server maybe waiting for someone to press ENTER key locally.
[{"Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwtcAAA","label":"Hardware"}],"ARM Case Number":"","Platform":[{"code":"PF016","label":"Linux"}],"Version":"All Version(s)"}]
Was this topic helpful?
Document Information
Modified date:
26 June 2024
UID
ibm17150128