Discussion:
OpenSSL Heartbleed Vulnerability Query
Mamabolo, Pheko
2014-04-10 10:34:00 UTC
Permalink
Hi

Does anyone know if Enterasys WLAN Controller that is running version 08.11.02.0023 could be running OpenSSL from 1.0.1 through 1.0.1f (i.e. inclusive) whether this has the Heartbleed vulnerability?

With best regards,
Pheko Mamabolo

Siemens (Proprietary) Limited
RC-ZA IT SD&CM N
300 Janadel Avenue
Midrand 1686, Südafrika
Tel: +27 11 652-2938
Fax: +27 86 506-6018
Mobile: +27 82 487-9822
mailto:***@siemens.com





------------------------------------

Disclaimer and
Confidentiality Note

This e-mail
communication, its attachments, if any, and any rights attaching to it are,
unless the context clearly indicates otherwise, the property of Siemens (Pty)
Ltd. It is confidential, private and intended for the addressee only. If you are
not the intended recipient and receive this communication in error, you are
hereby notified that any review, copying, use, discloser or distribution in any
manner whatsoever is strictly prohibited. Please notify the sender immediately
that you have received this e-mail in error and delete the e-mail and any copies
of it. Views and opinions expressed in this e-mail are those of the sender
unless clearly stated as those of Siemens (Pty) Ltd. Siemens (Pty) Ltd accepts
no liability for any loss or damage whatsoever, and howsoever incurred or
suffered resulting or arising from the use of this e-mail communication and/or
its attachments.

Siemens (Pty)
Ltd does not warrant the integrity of this e-mail communication nor that it is
free of errors, viruses, interception or interference.

Siemens (Pty)
Ltd, its divisions and subsidiary companies ("Siemens") expressly excludes
sections 11, 12, and 13 of the Electronic Communications and Transactions Act,
25 of 2002 ("the ECT") in respect of e-contracting. No data message or
electronic communication will be recognised as having a legal contractual status
under the ECT Act. All agreements concluded by Siemens will only be
legally binding when reduced to physical writing and physically signed by a duly
authorised representative of Siemens.

For more
information about Siemens (Pty) Ltd, visit our website at www.siemens.com



Siemens
(Proprietary) Limited

Company
Registration Number: 1923/007514/07

Registered
Address: 300 Janadel Avenue, Halfway House, 1685

VAT
Registration Number: 4790104428

Chairman: Prof
Dr S Russwurm *

Chief
Executive Officer: SG Proebstl * ; Chief Financial Officer: SU Dall'Omo
*

Executive
Directors: C Klaas; R Nkuhlu

Non-Executive
Directors: R Guntermann *; Dr MI Survé

Alternate
Directors: I Amod; Dr H Grundmann *

Company
Secretary: T Llale


* German

------------------------------------


---
To unsubscribe from enterasys, send email to ***@unc.edu with the body: unsubscribe enterasys gneu-***@gmane.org
enterasys@listserv.unc.edu
2014-04-10 10:34:39 UTC
Permalink
Hola buen día,

Estaré fuera de la oficina del Lunes 7 al viernes 18 de abril, tendré acceso limitado a mis correos de voz y electrónicos por lo que demorare en mi respuesta.
Si tu asunto requiere atención inmediata, por favor comunicarse con David Aguilar al teléfono 9000 1777, al celular 55 5217 3678 o al correo ***@netcontroll.com.

Saludos,
Gracias.


---
To unsubscribe from enterasys, send email to ***@unc.edu with the body: unsubscribe enterasys gneu-***@gmane.org
d***@fhsu.edu
2014-04-10 12:58:58 UTC
Permalink
<font face="Default Sans Serif,Verdana,Arial,Helvetica,sans-serif" size="2"><div><font face="Sans Serif, Verdana, Arial, Helvetica, sans-serif" size="2">I'm still running 08.32.01.0035 and can confirm it is <b>not</b> vulnerable.</font><br><br><font face="Verdana, Arial, Helvetica, sans-serif">If you have Internet access to the box, you can safely test yours using http://filippo.io/Heartbleed/</font></div><div style="font-family: Verdana, Arial, Helvetica, sans-serif;"><br></div><div style="font-family: Verdana, Arial, Helvetica, sans-serif;">To test my systems internally, I used the modified python script linked within the article below:</div><div><font face="Verdana, Arial, Helvetica, sans-serif">http://www.net-security.org/secworld.php?id=16661</font></div><div><br><br><font face="Verdana, Arial, Helvetica, sans-serif">Derek Johnson</font><br><font face="Verdana, Arial, Helvetica, sans-serif">Data Communications Coordinator</font><br><font face="Verdana, Arial, Helvetica, sans-serif">Fort Hays State University</font><br><font face="Verdana, Arial, Helvetica, sans-serif">(785) 628 - 5688</font><br><font face="Verdana, Arial, Helvetica, sans-serif">***@fhsu.edu</font></div><br><br><font color="#990099" style="font-family: Verdana, Arial, Helvetica, sans-serif;">-----"Mamabolo, Pheko" &lt;***@siemens.com&gt; wrote: -----</font><div style="font-family: Verdana, Arial, Helvetica, sans-serif; padding-left: 5px;"><div style="padding-right:0px;padding-left:5px;border-left:solid black 2px;">To: "Enterasys Customer Mailing List" &lt;***@listserv.unc.edu&gt;<br>From: "Mamabolo, Pheko" &lt;***@siemens.com&gt;<br>Date: 04/10/2014 05:34AM<br>Subject: [enterasys] OpenSSL Heartbleed Vulnerability Query<br><br> <!--Notes ACF <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">--> <!-- converted from rtf --> <font face="Calibri" size="2"><span style="font-size:11pt;"> <div>Hi </div> <div>&nbsp;</div> <div>Does anyone know if Enterasys WLAN Controller that is running version 08.11.02.0023 could be running OpenSSL from 1.0.1 through 1.0.1f (i.e. inclusive) whether&nbsp; this has the Heartbleed vulnerability?</div> <div>&nbsp;</div> <div><font face="Arial" size="2"><span style="font-size:10pt;">With best regards,</span></font></div> <div><font face="Arial" size="2"><span style="font-size:10pt;">Pheko Mamabolo</span></font></div> <div><font face="Arial" size="2"><span style="font-size:10pt;">&nbsp;</span></font></div> <div><font face="Arial" size="2"><span style="font-size:10pt;">Siemens (Proprietary) Limited</span></font></div> <div><font face="Arial" size="2"><span style="font-size:10pt;">RC-ZA IT SD&amp;CM N</span></font></div> <div><font face="Arial" size="2"><span style="font-size:10pt;">300 Janadel Avenue</span></font></div> <div><font face="Arial" size="2"><span style="font-size:10pt;">Midrand 1686, Südafrika</span></font></div> <div><font face="Arial" size="2"><span style="font-size:10pt;">Tel: +27 11 652-2938</span></font></div> <div><font face="Arial" size="2"><span style="font-size:10pt;">Fax: +27&nbsp; 86&nbsp; 506-6018</span></font></div> <div><font face="Arial" size="2"><span style="font-size:10pt;">Mobile: +27 82 487-9822</span></font></div> <div><a href="mailto:***@siemens.com"><font face="Arial" size="2" color="blue"><span style="font-size:10pt;"><u>mailto:***@siemens.com</u></span></font><font face="Arial" size="2" color="gray"><span style="font-size:10pt;"> </span></font></a></div> <div>&nbsp;</div> <div>&nbsp;</div> <div>&nbsp;</div> <div><font face="Arial" size="2"><span style="font-size:10pt;">&nbsp;</span></font></div> <div><font face="Arial" size="2"><span style="font-size:10pt;">&nbsp;</span></font></div> <div><font face="Arial" size="2"><span style="font-size:10pt;">------------------------------------<br> </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Disclaimer and </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Confidentiality Note</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">This e-mail </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">communication, its attachments, if any, and any rights attaching to it are, </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">unless the context clearly indicates otherwise, the property of Siemens (Pty) </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Ltd. It is confidential, private and intended for the addressee only. If you are </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">not the intended recipient and receive this communication in error, you are </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">hereby notified that any review, copying, use, discloser or distribution in any </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">manner whatsoever is strictly prohibited. Please notify the sender immediately </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">that you have received this e-mail in error and delete the e-mail and any copies </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">of it. Views and opinions expressed in this e-mail are those of the sender </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">unless clearly stated as those of Siemens (Pty) Ltd. Siemens (Pty) Ltd accepts </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">no liability for any loss or damage whatsoever, and howsoever incurred or </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">suffered resulting or arising from the use of this e-mail communication and/or </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">its attachments.</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Siemens (Pty) </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Ltd does not warrant the integrity of this e-mail communication nor that it is </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">free of errors, viruses, interception or interference.</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Siemens (Pty) </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Ltd, its divisions and subsidiary companies (“Siemens”) expressly excludes </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">sections 11, 12, and 13 of the Electronic Communications and Transactions Act, </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">25 of 2002 (“the ECT”) in respect of e-contracting.&nbsp; No data message or </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">electronic communication will be recognised as having a legal contractual status </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">under the ECT Act.&nbsp; All agreements concluded by Siemens will only be </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">legally binding when reduced to physical writing and physically signed by a duly </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">authorised representative of Siemens. </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">For more </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">information about Siemens (Pty) Ltd, visit our website at <a href="http://www.siemens.com">www.siemens.com</a></span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Siemens </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">(Proprietary) Limited</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Company </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Registration Number: 1923/007514/07</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Registered </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Address: 300 Janadel Avenue, Halfway House, 1685</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">VAT </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Registration Number: 4790104428</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Chairman: Prof </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Dr S Russwurm *</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Chief </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Executive Officer: SG Proebstl * ; Chief Financial Officer: SU Dall’Omo </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">*</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Executive </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Directors: C Klaas; R Nkuhlu</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Non-Executive </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Directors: R Guntermann *; Dr MI Survé</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Alternate </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Directors: I Amod; Dr H Grundmann *</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Company </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">Secretary: T Llale</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;</span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></font></div> <div><font face="Times New Roman" size="3"><span style="font-size:12pt;">* German</span></font></div> <div><font face="Arial" size="3"><span style="font-size:12pt;"><br> <font size="2"><span style="font-size:10pt;">------------------------------------</span></font></span></font></div> <div><font face="Arial" size="2"><span style="font-size:10pt;">&nbsp;</span></font></div> </span></font> <p></p><ul> <li> --To unsubscribe from enterasys, send email to <a href="mailto:***@unc.edu">***@unc.edu</a> with the body: unsubscribe enterasys ***@fhsu.edu </li></ul> </div></div><div></div></font>

<p><ul>

<li> --To unsubscribe from enterasys, send email to <a href="mailto:***@unc.edu">***@unc.edu</a> with the body: unsubscribe enterasys gneu-***@gmane.org
</ul>
Mamabolo, Pheko
2014-04-10 13:24:37 UTC
Permalink
Hi Derek,

Thank you, also see below.

https://community.extremenetworks.com/extreme/topics/heartbleed_openssl_vulnerability_in_nms_oneview_or_wireless_controller

Netsite 5.0.0.231
SIEM 7.7.2 Patch 1 (Build 614901 (7.2.0.614901))
use libssl.so.1.0.0.


NAC Gateway 5.0.0.231
uses libssl.so 0.9.8

So it looks like those versions are not vulnerable.


From: ***@fhsu.edu [mailto:***@fhsu.edu]
Sent: 10 April 2014 14:59
To: Enterasys Customer Mailing List
Subject: Re: [enterasys] OpenSSL Heartbleed Vulnerability Query

I'm still running 08.32.01.0035 and can confirm it is not vulnerable.

If you have Internet access to the box, you can safely test yours using http://filippo.io/Heartbleed/

To test my systems internally, I used the modified python script linked within the article below:
http://www.net-security.org/secworld.php?id=16661


Derek Johnson
Data Communications Coordinator
Fort Hays State University
(785) 628 - 5688
***@fhsu.edu<mailto:***@fhsu.edu>


-----"Mamabolo, Pheko" <***@siemens.com<mailto:***@siemens.com>> wrote: -----
To: "Enterasys Customer Mailing List" <***@listserv.unc.edu<mailto:***@listserv.unc.edu>>
From: "Mamabolo, Pheko" <***@siemens.com<mailto:***@siemens.com>>
Date: 04/10/2014 05:34AM
Subject: [enterasys] OpenSSL Heartbleed Vulnerability Query
Hi

Does anyone know if Enterasys WLAN Controller that is running version 08.11.02.0023 could be running OpenSSL from 1.0.1 through 1.0.1f (i.e. inclusive) whether this has the Heartbleed vulnerability?

With best regards,
Pheko Mamabolo


------------------------------------
Disclaimer and
Confidentiality Note

This e-mail
communication, its attachments, if any, and any rights attaching to it are,
unless the context clearly indicates otherwise, the property of Siemens (Pty)
Ltd. It is confidential, private and intended for the addressee only. If you are
not the intended recipient and receive this communication in error, you are
hereby notified that any review, copying, use, discloser or distribution in any
manner whatsoever is strictly prohibited. Please notify the sender immediately
that you have received this e-mail in error and delete the e-mail and any copies
of it. Views and opinions expressed in this e-mail are those of the sender
unless clearly stated as those of Siemens (Pty) Ltd. Siemens (Pty) Ltd accepts
no liability for any loss or damage whatsoever, and howsoever incurred or
suffered resulting or arising from the use of this e-mail communication and/or
its attachments.

Siemens (Pty)
Ltd does not warrant the integrity of this e-mail communication nor that it is
free of errors, viruses, interception or interference.

Siemens (Pty)
Ltd, its divisions and subsidiary companies (“Siemens”) expressly excludes
sections 11, 12, and 13 of the Electronic Communications and Transactions Act,
25 of 2002 (“the ECT”) in respect of e-contracting. No data message or
electronic communication will be recognised as having a legal contractual status
under the ECT Act. All agreements concluded by Siemens will only be
legally binding when reduced to physical writing and physically signed by a duly
authorised representative of Siemens.

For more
information about Siemens (Pty) Ltd, visit our website at www.siemens.com<http://www.siemens.com>



Siemens
(Proprietary) Limited

Company
Registration Number: 1923/007514/07

Registered
Address: 300 Janadel Avenue, Halfway House, 1685

VAT
Registration Number: 4790104428

Chairman: Prof
Dr S Russwurm *

Chief
Executive Officer: SG Proebstl * ; Chief Financial Officer: SU Dall’Omo
*

Executive
Directors: C Klaas; R Nkuhlu

Non-Executive
Directors: R Guntermann *; Dr MI Survé

Alternate
Directors: I Amod; Dr H Grundmann *

Company
Secretary: T Llale


* German

------------------------------------


* --To unsubscribe from enterasys, send email to ***@unc.edu<mailto:***@unc.edu> with the body: unsubscribe enterasys ***@fhsu.edu<mailto:***@fhsu.edu>

* --To unsubscribe from enterasys, send email to ***@unc.edu<mailto:***@unc.edu> with the body: unsubscribe enterasys ***@siemens.com<mailto:***@siemens.com>

---
To unsubscribe from enterasys, send email to ***@unc.edu with the body: unsubscribe enterasys gneu-***@gmane.org
Loading...