INTEL-SA-00075 Detection

Support-Anfragen für Server ohne Service

Support-Anfragen für Server ohne Service
Sie haben einen defekten Dell PowerEdge Server - dann sind Sie hier genau richtig!

INTEL-SA-00075 Detection

This question has been answered by DELL-Tom G

I got this message from the INTEL-SA-00075 Detection and Mitigation Tool:

What can I do, please?!

Risk Assessment

Based on the analysis performed by this tool, this system is vulnerable.

Explanation:

The detected version of the Management Engine firmware is considered vulnerable for INTEL-SA-00075.

If Vulnerable, contact your OEM for support and remediation of this system.

For more information, refer to CVE-2017-5689 in the following link: CVE-2017-5689

or the Intel security advisory Intel-SA-00075 in the following link: INTEL-SA-00075

INTEL-SA-00075 Detection Tool

Application Version: 1.0.2.116

Scan date: 2017-06-07 09:07:37

Host Computer Information

Name: XXX

Manufacturer: Dell Inc.

Model: Precision M6600

Processor Name: Intel(R) Core(TM) i7-2720QM CPU @ 2.20GHz

Windows Version: Microsoft Windows 10 Pro

ME Information

Version: 7.1.52.1176

SKU: Intel(R) Full AMT Manageability

Provisioning Mode: Not Provisioned

Control Mode: None

Is CCM Disabled: False

Driver installation found: True

EHBC Enabled: False

LMS service state: Running

microLMS service state: NotPresent

Verified Answer
  • Hi,

    You got that message because of the ME Firmware vulnerability. This is described here in detail.

    We are planning an bios update for this unit. Please check this whitepaper for more details. 

    Greetings

    Tom

  • hhmm :( 

    Normaly the command should remove the check of the ac adapter and not the batterry like I told before. :( Can you please try it with "/forceit" - hopefully that will work.

    Greetings

    Tom

All Replies
  • Hi,

    You got that message because of the ME Firmware vulnerability. This is described here in detail.

    We are planning an bios update for this unit. Please check this whitepaper for more details. 

    Greetings

    Tom

  • Hi Tom,

    thanks for your reply!

    Is it possible to install the Bios-Update without a battery?

    Diretctly from the Bios or with an USB-Stick?

    My battery is broken and when I start the Update this message appears:

    The AC adapter and battery must be plugged in before the system BIOS can be flashed.

  • Hi,

    Yes its possible. You need to open the console (CMD) with admin rights. Than type: bios executale and try it witth "/force" or "/forcetype" (e.g. bios.exe /force). This command should ignore the ac adapter and battery check before the update process.

    Thanks and Greetings

    Tom

  • Now i get the message:

    "Error: Invalide Command Line.

    Please verify the program was executed properly."

    I started the console with admin-rights ...

  • hhmm :( 

    Normaly the command should remove the check of the ac adapter and not the batterry like I told before. :( Can you please try it with "/forceit" - hopefully that will work.

    Greetings

    Tom

  • That's it!

    Thanks a lot ...

  • perfect :) thanks for your feedback!