The company provides information on how to address the issue

Apr 12, 2012 10:18 GMT  ·  By

The world renowned hardware manufacturer HP issued a security bulletin to warn HP ProCurve 5400 zl switch owners who purchased the device after April 30, 2011, that the compact flash cards contained in them may be infected with a virus that can spread to computers.

The company proposes two ways of resolving the issue. First, it has made available a script that’s designed for customers who don’t want to disrupt the uptime of their network. The script can be run using the “show tech custom” command and it deletes the malicious file and its directory without exposing the computing machine.

Those who may not like the “Software Purge Option” described before, or those who can afford to power down the switch can physically replace the Management Module.

“An advanced replacement Management Module will be sent to the customer. Once it arrives, the original Management Module is returned to HP after the new one is installed,” the bulletin reads.

HP provides the list of affected software versions along with the products’ serial numbers. The serial number of the HP ProCurve 5400 zl switch can be obtained by using the “show modules” command in a console session: • J9532A 5412zl-92GG-PoE+ / 2XG SFP+ v2 Switch • J9533A 5406zl-44G-PoE+ / 2XG SFP+ v2 Switch • J9539A 5406zl-44G-PoE+ / 4G SFP v2 Switch • J9540A 5412zl-92G-PoE+ / 4G SFP v2 Switch • J9642A HP E5406 zl Switch with Premium Software • J9643A HP E5412 zl Switch with Premium Software • J8697A HP E5406 zl Switch Chassis • J8698A HP E5412 zl Switch Chassis • J8699A - HP 5406-48G zl Switch • J8700A - HP 5412-96G zl Switch • J9447A - HP 5406-44G-PoE+-4SFP zl Switch • J9448A - HP 5412-92G-PoE+-4SFP zl Switch

J8726A Management Module in the 5400 series zl switch with the following serial numbers: ID116AS04P through ID116AS0HR and ID117AS00H through ID126AS0FB.

Serial numbers:

• ID030AS0MZ • ID034AS0QP • ID049AS0D4 • ID051AS074 • ID104AS06S • ID110AS0B6 • ID113AS0HH • ID113AS0K2 • ID113AS0KM • ID114AS00V • ID114AS02F • ID114AS03D • ID114AS08N • ID114AS0C8 • ID115AS08P • ID115AS097 • ID115AS0BL

The software purge script can be acquired from here.

Note. My Twitter account has been erroneously suspended. While this is sorted out, you can contact me via my author profile or follow me at @EduardKovacs1