7.2 Ensure system firmware updates are installed

Information

Security vulnerabilities and functional improvements are regularly addressed through firmware updates to the system and adapter firmware.

Unpatched system or adapter firmware can expose systems to known vulnerabilities that may be exploited by attackers. It is recommended that system and adadpter firmware updates be performed on enterprise assets on a regular basis.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Download the latest available from IBM FixCentral https://www.ibm.com/support/fixcentral/ for the identified hardware model and follow the provided instructions to apply to the system/adapter

Impact:

Flexible Service Processor (FSP) firmware should only be updated from the Hardware Management Console (HMC) which is responsible for the hardware.
I/O Adapter firmware should be updated from the LPAR to which the adapter is assigned.

See Also

https://workbench.cisecurity.org/benchmarks/22751

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4

Plugin: Unix

Control ID: 6a46f59af99a0cbd7584856dd707860ddee174c73a2e8656472f5596a2661152