back to article HPE tape library permits unauthorised remote access

HP Enterprise has warned that its StoreEver MSL6480 Tape Library is at risk of allowing “remote unauthorized disclosure of information.” As the MSL6480 can store up to 8.4 petabytes when all 560 of its slots are filled with LTO-7 tapes, that's rather a lot of data at risk. The problem isn't entirely HPE's fault: it derives …

  1. tom dial Silver badge

    Owners who care about their data should not manage these or similar devices in-band, and their out-of-band network should not be accessible from the public internet, for the same reasons that apply, for example, to water and power plants.

    A bit of critical thinking sometimes is useful

  2. Fedup

    Eh!

    How are you going to read the data off the tapes from the internal library controller via HTTP. The tape drives are connected via Fibre Channel to the backup server and all the data goes via the FC interface.

  3. Jon Massey
    Facepalm

    Wait a minute...

    An "enterprise" tape library runs PHP?!?!!

  4. toughluck

    That's a modern tape library with three access paths: data path, control path and out of band management interface. The data path and the control path can conceivably be on the same SAN, but the management interface is Ethernet.

    The vulnerability only affects the third portion above. Even if you have access to that interface, you still have no access to the control path or the data path.

    In short, you can't access data over the library management interface. (In theory you could over TTI, but that is unusable for slurping data since the interface throughput peaks at some 10 KB/s).

    Now, in a very stupid configuration, you could put the data and control paths on FCoE and then put them on the same LAN as the library management interface, but that has zero practical applications.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like