Operating System - HP-UX
1752369 Members
5919 Online
108787 Solutions
New Discussion

A VxWorks WDB Debug Agent is running on this host.

 
dictum9
Super Advisor

A VxWorks WDB Debug Agent is running on this host.

I have a Critical STIG item open on my rx8640 running 11.31. Actually on its console port. (Management processor).

This is the error message. what does it mean and how can I fix it? 

Could it be a problem with the firmware?

Management Processor Firmware revision B.002.005.010, Dec 8 2006 at 11:09:35

 

Arbitrary commands can be run on this port.   A VxWorks WDB Debug Agent is running on this host.

Using this service, it is possible to read or write any memory zone or execute arbitrary code on the host. An attacker can use this flaw to take complete control of the affected device." Disable the debug agent or contact the device's vendor for a patch.

7 REPLIES 7
Torsten.
Acclaimed Contributor

Re: A VxWorks WDB Debug Agent is running on this host.

1) even this is an old system, it does not run the latest firmware. You have bundle 3.0 or 3.1 running, latest was 4.2 including B.004.002003 for MP

 

2) I remember this was discussed here years ago, I cannot remember the thread or details, but I guess the result was it is not an issue - maybe google can help to find the thread.

 

However, if you want to continue to use this big block box, consider to bring it to the latest firmware level


Hope this helps!
Regards
Torsten.

__________________________________________________
There are only 10 types of people in the world -
those who understand binary, and those who don't.

__________________________________________________
No support by private messages. Please ask the forum!

If you feel this was helpful please click the KUDOS! thumb below!   
dictum9
Super Advisor

Re: A VxWorks WDB Debug Agent is running on this host.

How do I upgrade the firmware?

 

dictum9
Super Advisor

Re: A VxWorks WDB Debug Agent is running on this host.

/usr/lbin/sysrev
CIO 1.002 COMPLEX/CABINET/CORE I_O1
MP B.2.005.010 COMPLEX/CABINET/CORE I_O1
EVENT_DICT 2.006 COMPLEX/CABINET/CORE I_O1
CIO 1.002 COMPLEX/CABINET/SERVICE PROC
MP B.2.005.010 COMPLEX/CABINET/SERVICE PROC
EVENT_DICT 2.006 COMPLEX/CABINET/SERVICE PROC
GPM 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE
EMMUX 1.000 COMPLEX/CABINET/SYSTEM BACKPLANE
CELL_JTAG 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT3/CELL3
CELL_PDH 1.004 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT3/CELL3
CELL_LPM 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT3/CELL3
PDHC B.23.003.033 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT3/CELL3
IPF_FW 7.048 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT3/CELL3
CELL_JTAG 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT2/CELL2
CELL_PDH 1.004 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT2/CELL2
CELL_LPM 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT2/CELL2
PDHC B.23.003.033 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT2/CELL2
IPF_FW 7.048 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT2/CELL2
CELL_JTAG 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT1/CELL1
CELL_PDH 1.004 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT1/CELL1
CELL_LPM 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT1/CELL1
PDHC B.23.003.033 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT1/CELL1
IPF_FW 7.048 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT1/CELL1
CELL_JTAG 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT0/CELL0
CELL_PDH 1.004 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT0/CELL0
CELL_LPM 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT0/CELL0
PDHC B.23.003.033 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT0/CELL0
IPF_FW 7.048 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT0/CELL0
IO_LPM-0 1.003 COMPLEX/CABINET/MASTER I_O BAY/I_O CHASSIS0
IO_LPM-1 1.003 COMPLEX/CABINET/MASTER I_O BAY/I_O CHASSIS0

Torsten.
Acclaimed Contributor

Re: A VxWorks WDB Debug Agent is running on this host.

You need to find the bundle 4.2 (m_ipf_sx2000_4_2.tar.gz) at the support web site, you will find these files inside

m_ed.002.011.000.frm 476568
m_mp.004.002.003.frm 6581574

hm_pdhc.023.003.040.frm 806112
hm_ipf.009.066.000.frm 12584000
m_cell_jtag.001.002.000.frm 836134
m_cell_lpm.001.002.000.frm 1467263
m_cell_pdh.001.005.001.frm 5246318
m_io_lpm_0.001.004.000.frm 1463679
m_io_lpm_1.001.004.000.frm 1463679
m_ap_lpm_0.002.003.000.frm 1467601
m_ap_lpm_1.002.003.000.frm 1467601
m_emmux.001.000.000.frm 821051
m_gpm.001.002.000.frm 1463679
m_cio.001.002.000.frm 827778

 

and instructions how to do it.

Follow the instructions! Doing something wrong may brick the box.

 

 

http://h20565.www2.hpe.com/hpsc/swd/public/detail?sp4ts.oid=1844072&swItemId=ux_88078_1&swEnvOid=54#tab3

 

HP rx8640/rx7640 and Server Expansion Unit (SEU) Firmware

TITLE:HP rx8640/rx7640 and Server Expansion Unit (SEU) Firmware Release

VERSION: rx8640/rx7640 and SEU (AB301A) Firmware Version 4.2

Programmable Hardware:

  System Backplane GPM   	:   001.002.000
  System Backplane EMMUX 	:   001.000.000
  IO Backplane IO_LPM-0  	:   001.004.000
  IO Backplane IO_LPM-1  	:   001.004.000
  PCIe IO Backplane IO_LPM-0	:   002.003.000
  PCIe IO Backplane IO_LPM-1	:   002.003.000
  Core IO CIO            	:   001.002.000
  Cell_LPM               	:   001.002.000
  Cell_JTAG              	:   001.002.000
  Cell_PDH               	:   001.005.001
Firmware:
  Core IO MP             	: B.004.002.003
  Core IO ED			:   002.011.000
  Core IO SCSI FW             	:   001.003.035.070
  Core IO SCSI EFI Driver	:   001.005.004.000
  Cell PDHC              	: B.023.003.040
  Cell IPF_FW            	:   009.066.000

Hope this helps!
Regards
Torsten.

__________________________________________________
There are only 10 types of people in the world -
those who understand binary, and those who don't.

__________________________________________________
No support by private messages. Please ask the forum!

If you feel this was helpful please click the KUDOS! thumb below!   
dictum9
Super Advisor

Re: A VxWorks WDB Debug Agent is running on this host.

 When I try to login to download the file, I get this:

 

Could not open page

The service or information you requested is not available at this time.
Please try again later.

(Error: system-websrv_unavail)

dictum9
Super Advisor

Re: A VxWorks WDB Debug Agent is running on this host.

 

Upgrading the firmware did not resolve it.

>sysrev
CIO 1.002 COMPLEX/CABINET/CORE I_O1
MP B.4.002.003 COMPLEX/CABINET/CORE I_O1
EVENT_DICT 2.011 COMPLEX/CABINET/CORE I_O1
CIO 1.002 COMPLEX/CABINET/SERVICE PROC
MP B.4.002.003 COMPLEX/CABINET/SERVICE PROC
EVENT_DICT 2.011 COMPLEX/CABINET/SERVICE PROC
GPM 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE
EMMUX 1.000 COMPLEX/CABINET/SYSTEM BACKPLANE
CELL_JTAG 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT3/CELL3
CELL_PDH 1.004 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT3/CELL3
CELL_LPM 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT3/CELL3
PDHC B.23.003.033 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT3/CELL3
IPF_FW 7.048 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT3/CELL3
CELL_JTAG 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT2/CELL2
CELL_PDH 1.004 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT2/CELL2
CELL_LPM 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT2/CELL2
PDHC B.23.003.033 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT2/CELL2
IPF_FW 7.048 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT2/CELL2
CELL_JTAG 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT1/CELL1
CELL_PDH 1.004 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT1/CELL1
CELL_LPM 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT1/CELL1
PDHC B.23.003.033 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT1/CELL1
IPF_FW 7.048 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT1/CELL1
CELL_JTAG 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT0/CELL0
CELL_PDH 1.004 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT0/CELL0
CELL_LPM 1.002 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT0/CELL0
PDHC B.23.003.033 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT0/CELL0
IPF_FW 7.048 COMPLEX/CABINET/SYSTEM BACKPLANE/SLOT0/CELL0
IO_LPM-0 1.003 COMPLEX/CABINET/MASTER I_O BAY/I_O CHASSIS0
IO_LPM-1 1.003 COMPLEX/CABINET/MASTER I_O BAY/I_O CHASSIS0

>uname -a
HP-UX oracle B.11.31 U ia64 2283355874 unlimited-user license

Torsten.
Acclaimed Contributor

Re: A VxWorks WDB Debug Agent is running on this host.

Found some details in a discussion that I saved as a webpage years ago.

HP says more or less that no updates are/were planned for this obsolete product. The server itself is safe. They recommend to deny access to the port (UDP port 17185) via the network switch configuration and use an isolated network for management anyway.


Hope this helps!
Regards
Torsten.

__________________________________________________
There are only 10 types of people in the world -
those who understand binary, and those who don't.

__________________________________________________
No support by private messages. Please ask the forum!

If you feel this was helpful please click the KUDOS! thumb below!