cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
875
Views
0
Helpful
3
Replies

Cisco Secure Boot Vulnerability - PSIRT Not Clearing After Patching

GREGORY LEGGETT
Level 4
Level 4

I have two router models that I've applied the necessary patches to, ASR 1001-X (CSCvn89145) and ISR 4331 (CSCvn77156), and after uploading a new collection they are still reporting the issue.  There were IOS-XE upgrades performed in the same maintenance window, and the new version is reporting in SNTC; also the associated IOS-XE vulnerabilities are no longer listed.

 

Is there something that needs to be done to clear the patched devices, or should the PSIRT clear automatically after patching and uploading a new collection?

3 Replies 3

Chris Camplejohn
Cisco Employee
Cisco Employee

That PSIRT is only matching on SW Type and Hardware.  There is a caveat in our IC for it that states this.  We didn't have a list of all the affected versions to automate.  I'm not sure if SNTC portal is displaying that caveat to you.  For this specific PSIRT, it will not auto-clear, so you can just acknowledge it.

Is there a way to acknowledge the devices that I have patched, without clearing the PSIRT for all devices?  If not, I guess I will need to manually track which devices have been remediated.

Users with Admin permissions can acknowledge alerts.  See the online help documentation.