04-13-2020 05:11 PM
Hello,
I’ve been using SNTC portal to check on vulnerabilities of our equipment. On the portal, I do not see any vulnerabilities on 4500 series switch with the IOS version of 3.7.2E.
However, on Cisco software checker, I see bunch of vulnerabilities on the list for IOS version of 3.7.2E (see the attached spreadsheet)
I verified that CSPC has successfully collected and uploaded switch info to portal.
Can anyone advise why there's mismatch/missing vulnerabilities on the portal?
Thank you
04-13-2020 05:21 PM
04-20-2020 12:21 PM - edited 04-20-2020 12:25 PM
Does this mean switch can be vulnerable again if there's change in configuration? I still don't understand that there's a mismatch. I don't see any option to fix this on portal.
04-20-2020 12:58 PM
04-20-2020 01:04 PM
Yes they are running VSS.
04-20-2020 02:33 PM
@nader862010 I believe Austin Testut has internal discussion open on this topic as well. Initially we thought we had a bug with profiling of 4500 switch in this case, upon further analysis that does not seem to be an issue.
Please allow us some time to troubleshoot this more and I will get back with the update.
04-21-2020 01:23 PM
Hello all, it looks like there is a similar issue where the SNTC Portal is showing more PSIRTs for Nexus 5000's than in the IOS checker for 7.3(3)N1(1) and 7.3(0)N1(1). @Suchita Shewale I have sent you the excel files via the internal case.
Perhaps there is the same reason behind both of these PID's having differences in PSIRT totals?
04-23-2020 01:16 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide