D-Link Forums

D-Link Enterprise => DGS-1100-Series => Topic started by: nerux on June 17, 2017, 01:22:48 AM

Title: Reboot every 50 days + CVE
Post by: nerux on June 17, 2017, 01:22:48 AM
Hi,

Device Type    DGS-1100-24 Gigabit Ethernet Switch
Boot PROM Version    Ver 1.00.002
Firmware Version    Ver 1.01.018
Hardware Version    B1

I am proprietary of a DGS-1100-24 since 2 years. I had can see a maximum uptime arround 50 days, It reboot every 50 days. This switch is behind an UPS.

I monitor since september 2016 with munin and snmp :
(http://share.nerux.org/20170617_dgs-1100-24_uptime.png)
Code: [Select]
SNMPv2-MIB::sysDescr.0 = STRING: DGS-1100-24 Gigabit Ethernet Switch
SNMPv2-MIB::sysObjectID.0 = OID: SNMPv2-SMI::enterprises.171
DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (19705384) 2 days, 6:44:13.84

I am not sure that a real reboot, because I don't see an interruption on interfaces or services and don't see hole in interfaces's graph. Maybe it's the counter who's reset ?

In different searches about this problem I found this CVE-2016-10125 :(
https://labs.integrity.pt/advisories/dlink-dgs-1100-hardcoded-keys/ (https://labs.integrity.pt/advisories/dlink-dgs-1100-hardcoded-keys/)

Do you think realize a new firmware for fix this two points ?

Regards
Title: Re: Reboot every 50 days + CVE
Post by: FurryNutz on June 17, 2017, 08:25:43 AM
Link>Welcome! (http://forums.dlink.com/index.php?topic=48135.0)

Title: Re: Reboot every 50 days + CVE
Post by: nerux on June 17, 2017, 10:48:00 AM
France.
Title: Re: Reboot every 50 days + CVE
Post by: FurryNutz on June 17, 2017, 11:46:17 AM
I've passed this along to D-Link USA. I recommend that you phone contact your regional D-Link support office and ask for help and information regarding this. We find that phone contact has better immediate results over using email.
Let us know how it goes please.
Title: Re: Reboot every 50 days + CVE
Post by: nerux on June 17, 2017, 11:30:24 PM
Ok, thanks.
Title: Re: Reboot every 50 days + CVE
Post by: GreenBay42 on June 19, 2017, 06:39:05 AM
I received BETA firmware v1.01B35 to address this issue as well as other fixes. Let us know if this works for you.

Firmware File --> ftp://FTP2.DLINK.COM/PRODUCTS/DGS-1100-SERIES/DGS-1100_REVB_FIRMWARE_BETA_v1.01.B035.zip (ftp://FTP2.DLINK.COM/PRODUCTS/DGS-1100-SERIES/DGS-1100_REVB_FIRMWARE_BETA_v1.01.B035.zip)

Release Notes --> ftp://FTP2.DLINK.COM/PRODUCTS/DGS-1100-SERIES/DGS-1100_REVB_RELEASE_NOTES_BETA_v1.01.B035.pdf (ftp://FTP2.DLINK.COM/PRODUCTS/DGS-1100-SERIES/DGS-1100_REVB_RELEASE_NOTES_BETA_v1.01.B035.pdf)
Title: Re: Reboot every 50 days + CVE
Post by: FurryNutz on June 19, 2017, 10:06:23 AM
Thank you Sir.
Title: Re: Reboot every 50 days + CVE
Post by: nerux on June 19, 2017, 10:51:01 AM
Thanks.

Code: [Select]
2 1.01.B035 2572316 2017-03-12 07:45:31
md5sum 9e63f74b4190bbc4e539f71540c7b242  DGS1100-fw_1.01.B035.flash

Could you confirm me the md5sum of DGS1100-fw_1.01.B035.flash file ?

Boot up on beta firmware :
Code: [Select]
Boot PROM Version Ver 1.00.002
Firmware Version Ver 1.01.B035
*2c 1.01.B035 2572316 2017-03-12 07:45:31

The new firmware running on my switch, the configuration is safe.
The interface is slow when I visit the "VLAN" folder under "L2 features".
It arrives to freeze and not responding... I must power off / on the switch for get control, I will roll back.

I confirm the more stability of Ver 1.01.018.

Thanks for your help.

PS : I done the demand of support in europ, no response for the moment.

Best regards
Title: Re: Reboot every 50 days + CVE
Post by: GreenBay42 on June 20, 2017, 07:27:06 AM
I passed on your results to the product managers to report to the engineers.  Since support is based on region, please continue to contact your regional support and reference this forum. They may be able to get an older version (newer than build 18) for you.

I will post any new information here.
Title: Re: Reboot every 50 days + CVE
Post by: nerux on June 21, 2017, 03:31:30 PM
The european support reply with a new firmware : 1.01.B037 (2572316 2017-06-22 00:14:17)
This one show the same problem (freeze and instability) of version 1.01.B035 (2572316   2017-03-12 07:45:31).
I sent this to the support.

Regards
Title: Re: Reboot every 50 days + CVE
Post by: GreenBay42 on June 22, 2017, 06:38:59 AM
Thank you for the update.

You could try resetting the switch back to the default settings after the firmware upgrade, but you will need to configure it again.
Title: Re: Reboot every 50 days + CVE
Post by: nerux on June 22, 2017, 09:33:38 AM
Hello,

The european support give me a new firmware :
Code: [Select]
*2c 1.01.B038 2576212 2017-06-22 18:23:25
md5sum c9a5293b21e33f16591ce78d82b39e2a DGS1100-fw_1.01.B038(0426111023).flash

This new version of firmware seem to be stable without resetting the switch. I wait instructions of support team...

Regards
Title: Re: Reboot every 50 days + CVE
Post by: GreenBay42 on June 22, 2017, 09:36:06 AM
Keep us updated.