QRadar M6 xSeries firmware V2.0.0 for 1U and 2U appliances (USB On-prem installations)

Created by Jonathan Pechta on Mon, 09/21/2020 - 10:39
Published URL:
https://www.ibm.com/support/pages/node/6335253
6335253

Release Notes


Abstract

This firmware update (V2.0.0) provided by IBM is intended for xSeries firmware updates on your IBM® Security QRadar® M6 appliances. This update is intended for M6 1U and 2U form factor QRadar appliances where administrators want to update appliances using a bootable USB drive to complete an on-premise firmware update.

Content

Important: Select a tab to read each step of the firmware procedure.
 

Part 1: About the M6 firmware V2.0.0 update


Creating your USB flash drive for the firmware update requires a Windows™ host and the administrator must be on-site with the appliance. The firmware update can take up to 60 minutes complete per appliance and the administrator is required to reboot the appliance after the firmware install completes. The firmware upgrade procedures should only be done during a change window or during maintenance time for your QRadar appliances. If your Data Center does not allow USB keys, instructions and a download are available for administrators who have configured the XClarity interface on the Lenovo appliance. For information on how to install the ISO with your XClarity interface, see: https://www.ibm.com/support/pages/node/6335251.


 

Supported appliances, types, and model information


This firmware update applies to the following IBM Security QRadar M6 (1U and 2U form factor) appliance types:
Hardware Details
Appliance and Machine type models (MTM)
IBM QRadar Network Insights Appliance 1901 G2 (4563-F8Y)
IBM QRadar Network Insights Appliance 1910 G2 (4563-F7Y)
IBM QRadar Network Insights Appliance 1920 G2 (4563-F5F)
IBM QRadar Core Appliance XX29 G2 (4563-Q4A)
IBM QRadar Core Appliance XX48 G2 (4563-Q5B)
IBM QRadar Core Appliance XX05 G4 (4563-Q3E)
IBM QRadar Incident Forensics Appliance G4 (4563-F3A)
IBM QRadar Event/QFlow Collector Appliance 1501/1201 G4 (4563-Q5D)
IBM QRadar Network Packet Capture Appliance G2 (4563-F3C)
Server Type M6
Server Machine Type SR630 / M6 1U
SR650 / M6 2U
Table 1: List of appliances that the M6 appliance firmware V2.0.0 can update.

Important file changes and prerequisites in this firmware update


Administrators must ensure that their M6 appliance includes the minimum version outlined in the Prerequisite version column. If your M6 appliance does not meet the prerequisite versions outlined in the table, the administrator must contact IBM QRadar Support to discuss a custom upgrade path for your M6 appliance.
Component Prerequisite version Firmware version in this update File name 
UEFI/BIOS  None ive156l-2.61 lnvgy_fw_uefi_ive156l-2.61_anyos_32-64.uxz
XCC None cdo352t-4.20 oem_fw_xcc_cdo352t-4.20_anyos_noarch.uxz
LXPM None pdl126h-1.90 lnvgy_fw_lxpm_pdl126h-1.90_anyos_noarch.uxz
RAID Controller None 530-51.13.0-3427-0
930-51.13.0-3427-0
lnvgy_fw_sraidmr35_530-51.13.0-3427-0_linux_x86-64.bin
lnvgy_fw_sraidmr35_930-51.13.0-3427-0_linux_x86-64.bin
PCi and LOM adapters None 7.00-4.10-1.2203.0 intc-lnvgy_fw_nic_7.00-4.10-1.2203.0-all-b_linux_x86-64.bin

Note: PCi and LOM versions are the same as the M6 V1.1.0 release, no changes in firmware V2.0.0.
Emulex None 12.6.221.25-1 elx-lnvgy_fw_fc_19b-lp3x-12.6.221.25-1_linux_x86-64
Table 2: Firmware updates for the M6 QRadar form factor appliances are noted in this table.


NOTES
  • A number of hard disk drives can be installed in this appliance. The HDD update tool examines the hard disk drives that are present and selects the latest firmware version that is available for your drive.
  • The base system pack might contain other firmware packages that are not present in QRadar appliances. Firmware updates from the base system pack can be listed when the tool compares available firmware to the hardware in the appliance and display a status of "undetected".
  • For firmware questions and information see: http://ibm.biz/qradarfirmware.
 

Security issues resolved in this firmware update

The table below lists the software versions contained within the firmware package and the applicable CVEs addressed in this firmware release.

Component File name  CVEs resolved in this package
UEFI/BIOS lnvgy_fw_uefi_ive156l-2.61_anyos_32-64.uxz CVE-2020-0545, CVE-2020-0548, CVE-2020-0549, LEN-30483 and LEN-30689

Other issues resolved:
  • Resolved an issue when a system cannot boot from USB or PXE under "Legacy mode" after F12 (One Time Boot Device) key pressed.
  • Resolved an issue where the system cannot boot with command "ipmitool chassis bootdev disk" when in legacy mode.
  • Resolves an issue where the system cannot boot to USB harddisk when the boot priority of USB harddisk is higher than other harddisk.
  • Resolves an issue where Lenovo XClarity Administrator can not parse the setting UEFI.TrustedPlatformModule correctly.
  • Resolves an issue where CMM cannot apply or read power capping settings from SN550/SN850.
  • Resolves where the settings of Network Stack can not be loaded to default after clearing CMOS.
  • Resolves an AHCI mode issue when booting individual member of RAID 1 in RSTe, and it corrupts the RAID array.
  • Resolves PCIe slot devices missing after Enabling AdvancedRAS.PCIErrorRecovery.
  • Resolves a workaround for an uncorrectable PCIe error caused by the onboard VGA device when in legacy mode. The event log lists the error as: "An Uncorrectable PCIe Error has Occurred at Bus 0000 Device 00 Function 00. The Vendor ID for the device is 8086 and the Device ID is 2020. The Physical slot number is 0".
  • Improves memory performance for NUMA Optimized applications.
XCC oem_fw_xcc_cdo352t-4.20_anyos_noarch.uxz CVE-2015-3414, CVE-2015-3415, CVE-2015-3416, CVE-2016-6153, CVE-2017-3735, CVE-2017-3736, CVE-2017-3737, CVE-2017-3738, CVE-2017-5130, CVE-2017-6451, CVE-2017-6452, CVE-2017-6455, CVE-2017-6458, CVE-2017-6459, CVE-2017-6460, CVE-2017-6462, CVE-2017-6463, CVE-2017-6464, CVE-2017-7407, CVE-2017-8816, CVE-2017-8817, CVE-2017-10989, CVE-2017-12799, CVE-2017-12967, CVE-2017-13710, CVE-2017-14129, CVE-2017-14130, CVE-2017-14333, CVE-2017-14529, CVE-2017-14930, CVE-2017-14932, CVE-2017-14933, CVE-2017-14934, CVE-2017-14938, CVE-2017-14939, CVE-2017-14940, CVE-2017-14974, CVE-2017-15020, CVE-2017-15021, CVE-2017-15022, CVE-2017-15023, CVE-2017-15024, CVE-2017-15025, CVE-2017-15225, CVE-2017-15938, CVE-2017-15939, CVE-2017-15996, CVE-2017-16544, CVE-2017-16931, CVE-2017-16932, CVE-2017-17484, CVE-2017-1000100, CVE-2017-1000101, CVE-2017-1000254, CVE-2017-1000257, CVE-2017-1000494, CVE-2018-6872, CVE-2018-1000005, CVE-2018-1000007, CVE-2018-1000120, CVE-2018-1000121, CVE-2018-1000122
LXPM lnvgy_fw_lxpm_pdl126h-1.90_anyos_noarch.uxz None
RAID Controller lnvgy_fw_sraidmr35_530-51.13.0-3427-0_linux_x86-64.bin
lnvgy_fw_sraidmr35_930-51.13.0-3427-0_linux_x86-64.bin
None
PCi and LOM adapters intc-lnvgy_fw_nic_7.00-4.10-1.2203.0-all-b_linux_x86-64.bin None
Emulex elx-lnvgy_fw_fc_19b-lp3x-12.6.221.25-1_linux_x86-64 None
Table 3: Security issues resolved in the M6 firmware update V2.0.0.

Part 2: Requirements to create a bootable USB drive


To create a bootable USB key, you must have access to the following items:
  • An 8 GB or larger USB flash drive.
  • Entitlement for IBM Fix Central is required download firmware for QRadar appliances.
  • A workstation or laptop running one the following operating systems:
    • Windows™ 10
    • Windows™ 7
    • Windows™ Server 2008R2
    • Windows™ Server 20016
      NOTE: Microsoft, Windows, Windows NT, and the Windows logo are trademarks of Microsoft Corporation in the United States, other countries, or both.
 

Creating the bootable USB drive

  1. Download the M6 V2.0.0 firmware IMG file from IBM Fix Central.
    Note: Administrators can select either download link as the firmware download is identical for all QRadar software versions.  
  2. Download the Rufus Bootable USB Tool.
  3. Insert the USB flash drive into a USB port on your Windows™ laptop or workstation.
  4. Open Rufus and configure the properties.
    Parameter Value
    Device Select your USB drive
    Boot Selection Select Qradar_IMG_M6_1U_SR630_7X02_2U_SR650_7X06_2_0_0.img
    Partition scheme MBR (Default)
    Target system BIOS (or UEFI-CSM) (Default)
    File system FAT32 (Default)
    Cluster size
    This value defaults to the best option based on size of the USB drive.
     image 6271
  5. Click Start. The image is loaded on the USB drive.
    image 6272
  6. After the installation finishes, safely eject the USB flash drive from your computer.

    Results
    The bootable drive is ready to be used to install firmware on the M6 appliance.
 

Part 3. Installing the Firmware on the QRadar M6 appliance

The instructions below are intended for M6 appliances that are not configured as HA (high-availability) pairs. If your appliance is in a HA pair, you must use the High-Availability update instructions found here:  http://www.ibm.com/support/docview.wss?uid=swg27047121#HA .

Booting from the USB Drive

  1. Insert the USB drive that has the bootable image into the QRadar appliance.
    IMPORTANT: Do not remove the USB flash drive until the IBM ToolsCenter completes the firmware installation.
  2. From the terminal or the KVM switch for the appliance, log in with root user credentials.
  3. From the command prompt, type: reboot
  4. As the appliance reboots, press F12.
    image-20200313184743-1
  5. From the Boot Devices Manager, verify the Legacy Mode check boxes is clear (not selected).
    image-20200313184902-2
  6. Locate your USB drive in the Boot Devices Menu and press Enter.
    image-20200313185447-3
  7. In the Update Settings menu, verify all check boxes are clear (not selected) and click Next.
    image-20200313120252-24
  8. In the Update Comparison menu, click Begin.
    image-20200313120326-25
  9. The IBM UpdateXpress System Pack Installer compares the current package with the installed firmware.
  10. Verify all check boxes are selected where new firmware versions are available and click Next.
    IMPORTANT: Administrators must review the New Version column and confirm the firmware update is selected (checked). Issues have been reported previously where not all firmware changes were installed and administrators were required to run a firmware update two times to install updates.

    image-20200313120724-26
  11. Wait for the firmware updates to load.
    image-20200313121059-27
  12. Click Begin Update to install the firmware.
    image-20200313121201-28

    NOTE: Administrators might be prompted with a confirmation dialogue and need to click Next to continue.
    image-20200313121309-29
  13. Verify that all updates complete successfully and click Next.
    image-20200313121351-30
  14. If you experienced any errors, click Save Log or click Finish to exit after a successful installation.
    image-20200313121531-31
  15. The appliance must reboot to complete the firmware installation.
    image-20200313121704-32

    Results
    The appliance reboots and is available for use in the QRadar deployment. If you experience any installation issues, you can contact QRadar Support for assistance and open a software support case for your appliance. The support representative can request the firmware logs for review to determine the root cause of the issue or if replacement hardware is required. If the issue is hardware related, the support representative can change the case type and involve the proper teams to schedule replacement parts.  
 

[{"Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwtcAAA","label":"Hardware"}],"ARM Case Number":"","Platform":[{"code":"PF016","label":"Linux"}],"Version":"All Version(s)"}]

Document Information

Modified date:
06 October 2020

UID

ibm16335253