Dell acknowledges malicious code
Posted by Peter Streips on Thu, Jul 29, 2010 @ 07:23 PM
“I just got a telephone call from a service scheduler informing me that the replacement R410 motherboard I received several weeks ago contains spyware in its embedded systems management firmware, and wanting to schedule an additional service call for a tech to come clean it off.” A customer quote from the Dell Support forum.
Dell responded by taking responsibility and publishing the following note from Forrest Norrod, Vice President and General Manager of Server Platforms. “Dell is aware of the issue and is contacting affected customers. The issue affects a limited number of replacement motherboards in four servers - PowerEdge R310, PowerEdge R410, PowerEdge R510 and PowerEdge T410 – and only potentially manifests itself when a customer has a specific configuration and is not running current anti-virus software. This issue does not affect systems as shipped from our factory and is limited to replacement parts only. Dell has removed all impacted motherboards from its service supply chain and new shipping replacement stock does not contain the malware.”
This just further ratifies the importance of quality control in manufacturing, and the role that anti-virus and anti-malware software needs to play in that process. This is even a larger issue for Dell customers as these are server motherboards and not desktop motherboards as most servers in most organizations cannot just be shut off whenever a technician shows up with a replacement part, downtime needs to be scheduled in advance. What might make things worse is that this issue is only affecting replacement boards, so the downtime has already be scheduled and motherboards already replaced in some cases…all to find out that it has to be done again.