Introduction
Remediation of CVE-2024-20356 requires an update to the CIMC firmware for the Cisco Secure Endpoint Private Cloud appliance. This article describes the process of upgrading the firmware of a Private Cloud UCS appliance.
Prerequisites
- Secure Endpoint Private Cloud UCS Appliance with Private Cloud version 3.9.x or above.
- Access to the Private Cloud UCS Appliance CIMC web UI (including access to the web based KVM).
Required Downtime
The firmware upgrade takes approximately 40 minutes to complete. During this time the Cisco Secure Endpoint functionality will not be available.
After the firmware upgrade is complete, the UCS appliance will be rebooted. This can take another 10 minutes.
Total downtime is approximately 50 minutes.
Firmware Upgrade Steps
Proxy or Connected Mode
- Run the following commands on the appliance command line (either through SSH or CIMC KVM): yum install -y ucs-firmware
- In your web browser, log into the CIMC web UI of the appliance and open the KVM console.
- Reboot the appliance with (either from SSH or the CIMC KVM console): amp-ctl reboot
- In the CIMC KVM console, wait for the appliance to reboot. In the boot loader menu, a new "UCS Appliance Firmware Update" menu item will be available (see screenshot below).
- The boot loader will wait a couple of seconds before booting the normal appliance. Use the down arrow to select "UCS Appliance Firmware Update" and press enter.
- The appliance will boot into the firmware updater, update the firmware and reboot the appliance.
- The CIMC may log you out during this process.
Airgap Mode
- Create a new update ISO using amp-sync.
- Mount the update ISO as for a normal appliance update.
- Run the following commands on the appliance command line (either through SSH or CIMC KVM): yum install -y ucs-firmware
- In your web browser, log into the CIMC web UI of the appliance and open the KVM console.
- Reboot the appliance with (either from SSH or the CIMC KVM console): amp-ctl reboot
- In the CIMC KVM console, wait for the appliance to reboot. In the boot loader menu, a new "UCS Appliance Firmware Update" menu item will be available (see screenshot above).
- The boot loader will wait a couple of seconds before booting the normal appliance. Use the down arrow to select "UCS Appliance Firmware Update" and press enter.
- The appliance will boot into the firmware updater, update the firmware and reboot the appliance.
- The CIMC may log you out during this process.
Verification Steps
- In the CIMC web UI, go to the menu: Admin -> Firmware Management (see example screenshot below).
- The BMC version should be 4.3(2.240009).