THIS FIELD NOTICE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTY OF MERCHANTABILITY. YOUR USE OF THE INFORMATION ON THE FIELD NOTICE OR MATERIALS LINKED FROM THE FIELD NOTICE IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS FIELD NOTICE AT ANY TIME.
Revision | Publish Date | Comments |
---|---|---|
1.0 |
19-May-17 |
Initial Release |
10.0 |
18-Oct-17 |
Migration to new field notice system |
10.1 |
14-Jan-19 |
Fixed Broken Image Links and Formatting |
Affected Product ID | Comments |
---|---|
CDE250-HV-2WPL-K9= |
|
CDE250-K9 |
|
CDE250-XR-2WPL-K9= |
Defect ID | Headline |
---|---|
CSCvc18598 | CDE250 IPMI FW older than v3.12 have a weak cypher issue that is fixed in the CDE250 IPMI v3.12 |
CSCve34374 | CDE250 the i2C bus can hang because of contention on the i2C bus |
This Field Notice addresses two issues on the Content Delivery Engine 250 (CDE250):
Cipher is an algorithm used to perform encryption or decryption in the SSH protocol. The CDE250 IPMI firmware versions 3.09 and earlier have weak cipher. The CDE250 system utilizes IPMI in order to monitor and manage the health of the system. This function is implemented with embedded IPMI firmware that runs within the Baseboard Management Controller (BMC) that resides on the motherboard. The new security enhancement in IPMI version 3.12 improves the cipher.
The SDT utility versions 2.112 and earlier directly access the BMC and do not validate the I2C bus availability. This possibly causes contention issues which could result in I2C bus hang. SDT version 2.113 addresses this particular issue.
There is no error message for the weak cipher.
This symptom can be observed for the I2C hang issue:
Cisco recommends that these steps be taken in order to update the IPMI for VDS-TV, VQE, and VDS-IS applications and the SDT utility for VDS-TV and VD-IS applications. This update needs to be done during a maintenance window.
Product ID | IPMI FW Version | Action |
---|---|---|
CDE250-K9 | FW version = 3.12 or later (SDT v2.113 required) | Unit is good, no action required |
CDE250-K9 | FW version = 1.33 or 2.05 or 3.03, 3.06 or 3.09 | Upgrade IPMI FW |
For further details, refer to the IPMI Firmware v3.12 and SDT 2.113 Upgrade instructions.
For the VDS-IS application, patches have been developed in order to upgrade the SDT version 2.113 as it is required for the new IPMI FW.
VDS-IS Release | IPMI FW | HW platform | Impact | Action | Required Patch |
---|---|---|---|---|---|
3.x | 3.12 and later | CDE250-K9 | All customers that use version 3.x up to the latest 3.3.1b138 imaged | Apply the corresponding patch in VDS-IS to upgrade the SDT version to 2.113 | IPMI_VDS-IS_3x_SDT-2.113_Patch |
4.x | 3.12 and later | CDE250-K9 | All customers that use version 4.x up to the latest 4.3.2-b28 image | Apply corresponding patch in VDS-IS to upgrade the SDT version to 2.113 | IPMI_VDS-IS_4x_SDT-2.113_Patch |
Update the VDS-IS Application with the Script
Refer to the Release Notes and IPMI Firmware downloads for further details:
The hardware information can be obtained either with a CLI command or a physical inspection of the chassis. The CLI command as shown in this screenshot must be used in order to determine the IPMI FW version.
Command Line
CDE Product ID Information
Visual Inspection
In order to identify the affected chassis, check the Product ID (PID) located on the right front corner of the top of the chassis.
This label is located on top right front corner of the chassis.
If you require further assistance, or if you have any further questions regarding this field notice, please contact the Cisco Systems Technical Assistance Center (TAC) by one of the following methods:
Cisco Notification Service—Set up a profile to receive email updates about reliability, safety, network security, and end-of-sale issues for the Cisco products you specify.