cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5390
Views
1
Helpful
27
Replies

CSPC Security Vulnerability CVE-2016-1908

IOCNetwork1911
Level 1
Level 1

Number for SSH vulnerability: CSPC Security Vulnerability 

Description: OpenSSH Improper Failed Cookie Generation Handling Vulnerability

Please advise a method on finding the existing OpenSSH version of the CSPC from GUI.

27 Replies 27

IOCNetwork1911
Level 1
Level 1

Hi @jboyanob  : tried to upgrade Current version is 2.8.1.9 through GUI. But No latest version is available for download from the "Software updates" tab in the CSPC collector. It says "Collector Software is latest and up-to-date.
No action required. You will be informed as soon as new updates are available".  

please let me know how should it be upgraded , through CLI or GUI  . Also , is there a path of upgrade like 2.8 > 2.9 > 2.10 

screenshot is attached from the CSPC collector showing the "software update" tab

jboyanob
Cisco Employee
Cisco Employee

Hello, @IOCNetwork1911 

I hope you are having a great day

There is no direct path upgrade from 2.8 to 2.10 versions.

In this case you should install first a new 2.10.0.1 OVA File and then install the 2.10.0.7 patch manually.

You can find the steps attached in the files previously shared on the thread:

 

Kindest regards,

IOCNetwork1911
Level 1
Level 1

Hi @jboyanob : is there backup to taken before upgrade ? can you please share me the steps to take backup

Can the upgrade be done on the current virtual machine running on 2.8 version ?

can you please share the image to be used ? 

Is the image given below the right one ? 

 
Virtual Machine image for deploying on environments like VMware Esxi
Collector-2.10.0.1-B-7.ova

IOCNetwork1911
Level 1
Level 1

@jboyanob : Also, please advice how can we add the existing inventory information and data in the new virtual machine ?

How to take the information in backup so that it can be added to 2.10.1 version. will the Backup taken from 2.8 be compatible with 2.10.1 version ?

jboyanob
Cisco Employee
Cisco Employee

Hello @IOCNetwork1911 

I hope you are doing great.

Collector-2.10.0.1-B-7.ova is the OVA file that you should use to install a new CSPC.  https://software.cisco.com/download/home/286312935/type/286312958/release/2.10.0.1 

Here the file for the 2.10.0.7 patch: https://software.cisco.com/download/home/286312935/type/286312958/release/2.10.0.7 

For the backup, you should be able to backup the collector by following the instructions on CSPC User Guide (attached file). Chapter 9- Section 9-10 Backup and restore.

You have also the option to export the SNMP credentials and then import it into the new collector and to add the list of IP addresses when you perform the discovery on the new collector.

Kindest regards,

IOCNetwork1911
Level 1
Level 1

@jboyanob : new VM is deployed with OVA file of 2.10.1 version. But while trying to register the CSPC collector , VM got unreachable. Now VM is restarted and became reachable. What are the steps to register and import the inventory from csv files ? please advice. since there is no FTP , SFTP or local server, backup could not be taken.

IOCNetwork1911
Level 1
Level 1

How to get the CCO ID credentials to register CPSC with Cisco server ?

IOCNetwork1911
Level 1
Level 1

Is it possible to restore backup from version 2.8 ? is it compatible ? if so , what are the steps for backup by CLI to do this ? 

IOCNetwork1911
Level 1
Level 1

@jboyanob : Is it possible to restore backup from version 2.8 ? is it compatible ? if so , what are the steps for backup by CLI to do this ? 

How can i raise a TAC case for taking backup. i am not able to get the backup file.

jboyanob
Cisco Employee
Cisco Employee

Hello, @IOCNetwork1911 

I hope you are doing great.

If you are having issues with backup file, you can use the option of export SNMP Credentials by clicking on Credentials>Export and use the XML format. For managed devices use CSV format and then when you are in the new collector, you can import the credentials and then copy a list of IP addresses to discover again the devices.

For open a TAC case, you can go to www.cisco.com  by going to 'Support' > 'Open a Case'. You might need your Cisco service contract numbers and other details related to your company's account.

 

Kindest regards,

Hi @jboyanob 

We had to redeploy the CSPC due to the recent vulnerabilities. Now we need to add a registration certificate to the new collector, however my Cisco ID does not allow to view the section for this task at the services portal under Library > Administration > All Collectors.

Could you please assist us to provide permission for this task in the Services portal?

Thank you,

IOCNetwork1911
Level 1
Level 1

@jboyanob : can you please share the contract details of CSPC with which i raise a TAC case for CSPC

jboyanob
Cisco Employee
Cisco Employee

Hello, @IOCNetwork1911 

I hope you are doing great.

Can you please publish a new post for the question/issue with certificate for CSPC. 

We will be glad to assist.

Kindest regards,