Sie sind auf Seite 1von 7

[Type here]

Appliance Firmware Update Tool Release Notes

11-Dec-2020

The Veritas Appliance firmware update tool is a replacement for the Manage > Software >
Firmware command. Starting with NetBackup Appliance release 3.1.1, this tool is the
recommended method for firmware updates.

The firmware update is packaged as an Emergency Engineering Binary (EEB). Firmware


update EEBs are currently available for the following appliance platforms and their associated
software versions:

• NetBackup Appliance 3.3.0.1 – Release 12


• NetBackup Appliance 3.2 – Release 12
• NetBackup Appliance 3.1.2 – Release 12
• NetBackup Appliance 3.1.1 – Release 10

On 3.3.0.1, install Maintenance Release 1 (MR1) before installing the firmware update EEB.
Attempting to install MR1 after installing firmware update EEB will require first
uninstalling firmware update EEB before MR1 installation can continue. Note that
uninstalling the firmware update EEB does not revert the firmware changes.

The EEB installs the Veritas Standalone firmware Update and Recovery Environment. This is a
standalone operating system which is booted by the appliance to deploy the firmware updates
in a controlled and isolated environment. Upon completion of the firmware updates, the
appliance automatically reboots back into the primary application operating system.

If an earlier version of this EEB is already installed, you must uninstall the previous EEB
first before installing the updated version.

Required appliance reboot after Firmware Update Tool EEB installation

After the EEB installation has completed successfully, you must reboot the appliance. The
appliance firmware update begins automatically during the reboot. While the firmware update
is in progress, users are unable to access or log in to the appliance through the appliance shell
menu or the appliance web console. The firmware update process can be viewed by using the
IPMI console or a physical console connection on the appliance.

The final stage of the firmware update includes updating the system BIOS. The BIOS update
will disconnect all active IPMI console sessions. When the firmware and BIOS update processes
have completed, the appliance reboots into the normal appliance application OS.

Note: When installing this EEB on appliance nodes in a High Availability (HA) setup, update
one node at a time. Start with the partner node where the MSDP services are offline. After the
[Type here]
Appliance Firmware Update Tool Release Notes

EEB installation, the firmware update, and the BIOS update have all completed successfully,
perform a switchover so that the updated partner node takes over running the MSDP services.
Then, update the other compute node. After the EEB installation, and the firmware and BIOS
have been updated successfully, perform a switchover to return the HA setup back to its
normal operations.

Estimated time for firmware update

• NetBackup Appliance models 5230/5330/5240/5250: 2 hours


• NetBackup Appliance model 5340: 3 hours

After the firmware update has completed and the system is booted back into the normal
appliance operating system, the firmware report and debug logs can be found in the following
locations:

• Final report
/log/sure/#DATE#/sure_final_update_report.txt (Example: /log/sure/20191126204549/
sure_final_update_report.txt)
• Detailed debug logs:
/log/sure/#DATE#/sure.log

Uninstalling the Firmware Update Tool EEB

To uninstall the EEB, use the Manage > Software > Rollback command.

Uninstalling the EEB does not revert the firmware changes

Re-running the firmware update

If you want to run the firmware update EEB again, you must uninstall the EEB and then re-
install the EEB.

Vulnerabilities Fixed in Release 12


Binary Name: NBAPP_EEB_ET4011834-3.3.0.1-12-x86_64.rpm

Binary Name: NBAPP_EEB_ET3987003-3.2.0.0-12.x86_64.rpm

Binary Name: NBAPP_EEB_ET3987548-3.1.2.0-12.x86_64.rpm


[Type here]
Appliance Firmware Update Tool Release Notes

All fixes in release 12 apply to 5250/5340 appliance model only


All fixes addressed in previous release carry over to release 12.
This is the first release for 3.3.0.1

- Intel® CSME, SPS, TXE, AMT and DAL Technical Advisory PSIRT-TA-201910-001, ( INTEL-SA-
00295)
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html
CVE-2020-0545 : https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0545

- Intel® Processors Data Leakage Technical Advisory PSIRT-TA-201912-012, (INTEL-SA-00329)


https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00329.html
CVE-2020-0548 : https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0548
CVE-2020-0549 : https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0549

Hardware component versions included in Release 12

Binary Name: NBAPP_EEB_ET4011834-3.3.0.1-12-x86_64.rpm

Binary Name: NBAPP_EEB_ET3987003-3.2.0.0-12.x86_64.rpm

Binary Name: NBAPP_EEB_ET3987548-3.1.2.0-12.x86_64.rpm

Component Vendor Model Sub-Module Version


Type
BIOS Intel S2600WTT SE5C610.86B.01.01.0029
S2600WF0 SE5C620.86B.02.01.0012
S2600GZ SE5C600.86B.02.06.0007
HBA LSI RS3UC080 15.00.01.00
HDD Seagate ST1000NM0023 E007
ST3000NM0023 E007
ST6000NM0034 E0G5
ST3000NM0025 N004
ST1000NM0045 N004
ST4000NM0025 N004
ST6000NM0095 E005
ST10000NM0096 E005
JBOD Seagate SP-3212 Canister 1 4.0.0.124
Canister 2 4.0.0.124
Midplane VPD 0x0C
Midplane 0x14
CPLD
PCM1 3.3D|3.0A
PCM2 3.3D|3.0A
Network Intel X710-DA2 6.01
[Type here] Appliance Firmware Update Tool Release Notes

RAID Intel RMS3CC080 24.21.0-0091


Controller
RS3SC008 24.21.0-0091
RMS3HC080 24.21.0-0091
RS25SB008 23.34.0-0019
RMS25CB080 23.34.0-0019
RBOD NetApp RBOD 8.25.14.00
NVSRAM N5501-825898-001
EBOD 039F
Storage Veritas 5865 (5005) GN260R008
Controller (Seagate)
5565 (5005) GN260R008

Vulnerabilities Fixed in Release 9

All fixes in release 9 apply to 5240 appliance model only

- Intel® CSME, SPS, TXE, & AMT Updates (PSIRT-TA-201901-002) RDC# 607858
Security Advisory INTEL-SA-00213 disclosing CVE-2019-0089, CVE-2019-0090, CVE-2019-
0086, CVE-2019-0091, CVE-2019-0092, CVE-2019-0093, CVE-2019-0094, CVE-2019-0096,
CVE-2019-0097, CVE-2019-0098, CVE-2019-0099, CVE-2019-0153, CVE-2019-0170
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00213.html

- UEFI Updates (PSIRT-TA-201901-006) RDC# 608879


Security Advisory INTEL-SA-00223 disclosing CVE-2019-0119, CVE-2019-0120, CVE-2019-0126
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-
00223.html?wapkw=INTEL-SA-00223

- Intel® Processor Microcode Updates (PSIRT-TA-2019-02-002) RDC# 608917


Security Advisory INTEL-SA-00233 disclosing CVE-2018-12126, CVE-2018-12127, CVE-2018-
12130 and CVE-2019-11091
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00233.html

- 2019.2 IPU - 2019.2 IPU - Machine Check Error on Page Size Change Vulnerability Technical
Advisory (PSIRT-TA-201811-010 )
Security Advisory INTEL-SA-00210 disclosing CVE-2018-12207
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00210.html

- 2019.2 IPU - Sighting Report for SINIT_ACM_Intel® TXT, PSIRT-TA-201905-007 (CVE-2019-


0124)
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00220.html
[Type here]
Appliance Firmware Update Tool Release Notes

- 2019.2 IPU - Intel® CPU Local Privilege Escalation Technical Advisory, PSIRT-TA-201905-004
Security Advisory INTEL-SA-00240 disclosing CVE-2019-0151 and CVE-2019-0152
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00240.html

- 2019.2 IPU BIOS Technical Advisory, PSIRT-TA-201907-005


Security Advisory INTEL-SA-00280 disclosing CVE-2019-11136, CVE-2019-11137
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00280.html

Enhancements in Release 9
• 5240 RAID controller update issue

Hardware component versions included in Release 9

Binary Name: NBAPP_EEB_ET3987003-3.2.0.0-9.x86_64.rpm

All versions listed below are carried over from release 8, except for 5240 BIOS
(SE5C610.86B.01.01.0029) update

Component Vendor Model Sub-Module Version


Type
BIOS Intel S2600WTT SE5C610.86B.01.01.0029
S2600WF0 SE5C620.86B.02.01.0010
S2600GZ SE5C600.86B.02.06.0007
HBA LSI RS3UC080 15.00.01.00
HDD Seagate ST1000NM0023 E007
ST3000NM0023 E007
ST6000NM0034 E0G5
ST3000NM0025 N004
ST1000NM0045 N004
ST4000NM0025 N004
ST6000NM0095 E005
ST10000NM0096 E005
JBOD Seagate SP-3212 Canister 1 4.0.0.124
Canister 2 4.0.0.124
Midplane VPD 0x0C
Midplane 0x14
CPLD
PCM1 3.3D|3.0A
PCM2 3.3D|3.0A
Network Intel X710-DA2 6.01
RAID Intel RMS3CC080 24.21.0-0091
Controller
RS3SC008 24.21.0-0091
RMS3HC080 24.21.0-0091
RS25SB008 23.34.0-0019
[Type here]
Appliance Firmware Update Tool Release Notes

RMS25CB080 23.34.0-0019
RBOD NetApp RBOD 8.25.14.00
NVSRAM N5501-825898-001
EBOD 039F
Storage Veritas 5865 (5005) GN260R008
Controller (Seagate)
5565 (5005) GN260R008

Fixes are cumulative. Previous releases of the appliance firmware update tool had fixes for
other appliance models as well. So, if you have never installed the firmware update tool,
please install it on NetBackup Appliance 3.2 or 3.1.2 irrespective of appliance model.

Enhancements in Release 10 for 3.1.1 ONLY


Binary Name: NBAPP_EEB_ET3987546-3.1.1.0-10.x86_64.rpm

• 5240 RAID controller update issue

Hardware component versions included in Release 10 for 3.1.1 ONLY

Binary Name: NBAPP_EEB_ET3987546-3.1.1.0-10.x86_64.rpm

Component Vendor Model Sub-Module Version


Type
BIOS Intel S2600WTT SE5C610.86B.01.01.0028
S2600WF0 SE5C620.86B.02.01.0010
S2600GZ SE5C600.86B.02.06.0007
HBA LSI RS3UC080 15.00.01.00
HDD Seagate ST1000NM0023 E007
ST3000NM0023 E007
ST6000NM0034 E0G5
ST3000NM0025 N004
ST1000NM0045 N004
ST4000NM0025 N004
ST6000NM0095 E005
ST10000NM0096 E005
JBOD Seagate SP-3212 Canister 1 4.0.0.124
Canister 2 4.0.0.124
Midplane VPD 0x0C
Midplane 0x14
CPLD
PCM1 3.3D|3.0A
PCM2 3.3D|3.0A
[Type here]
Appliance Firmware Update Tool Release Notes

Network Intel X710-DA2 6.01


RAID Intel RMS3CC080 24.21.0-0091
Controller
RS3SC008 24.21.0-0091
RMS3HC080 24.21.0-0091
RS25SB008 23.34.0-0019
RMS25CB080 23.34.0-0019
RBOD NetApp RBOD 8.25.14.00
NVSRAM N5501-825898-001
EBOD 039F
Storage Veritas 5865 (5005) GN260R008
Controller (Seagate)
5565 (5005) GN260R008

Das könnte Ihnen auch gefallen