Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000190266


DSA-2021-140: Dell EMC Cloud Tiering Appliance Security Update for Multiple Third-Party Component Vulnerabilities

Summary: Dell EMC Cloud Tiering Appliance remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.

Article Content


Impact

High

Details

Third-party Component CVEs More information
grub2
grub2-snapper-plugin
grub2-i386-pc
grub2-systemd-sleep-plugin
CVE-2020-14372 https://www.suse.com/security/cve/CVE-2020-14372/
CVE-2020-25632
 
https://www.suse.com/security/cve/CVE-2020-25632/
 
CVE-2020-25647
 
https://www.suse.com/security/cve/CVE-2020-25647/
 
CVE-2020-27749
 
https://www.suse.com/security/cve/CVE-2020-27749/
 
CVE-2020-27779
 
https://www.suse.com/security/cve/CVE-2020-27779/
 
CVE-2021-20225
 
https://www.suse.com/security/cve/CVE-2021-20225/
 
CVE-2021-20233 https://www.suse.com/security/cve/CVE-2021-20233/
Third-party Component CVEs More information
grub2
grub2-snapper-plugin
grub2-i386-pc
grub2-systemd-sleep-plugin
CVE-2020-14372 https://www.suse.com/security/cve/CVE-2020-14372/
CVE-2020-25632
 
https://www.suse.com/security/cve/CVE-2020-25632/
 
CVE-2020-25647
 
https://www.suse.com/security/cve/CVE-2020-25647/
 
CVE-2020-27749
 
https://www.suse.com/security/cve/CVE-2020-27749/
 
CVE-2020-27779
 
https://www.suse.com/security/cve/CVE-2020-27779/
 
CVE-2021-20225
 
https://www.suse.com/security/cve/CVE-2021-20225/
 
CVE-2021-20233 https://www.suse.com/security/cve/CVE-2021-20233/
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

CVEs Addressed Product Affected Versions Updated Versions Link to Update
CVE-2020-14372
CVE-2020-25632
CVE-2020-25647
CVE-2020-27749
CVE-2020-27779
CVE-2021-20225
CVE-2021-20233
Cloud Tiering Appliance
 
Versions 13.0.0.0.16 to 13.0.0.3.21
 
13.0.0.3.25 For CTA and CTA-HA:
https://www.dell.com/support/home/en-in/product-support/product/cloud-tiering-appliance/drivers
For CTA/VE and CTA-HA/VE:
https://www.dell.com/support/home/en-in/product-support/product/cloud-tiering-applianceve/drivers
 
CVEs Addressed Product Affected Versions Updated Versions Link to Update
CVE-2020-14372
CVE-2020-25632
CVE-2020-25647
CVE-2020-27749
CVE-2020-27779
CVE-2021-20225
CVE-2021-20233
Cloud Tiering Appliance
 
Versions 13.0.0.0.16 to 13.0.0.3.21
 
13.0.0.3.25 For CTA and CTA-HA:
https://www.dell.com/support/home/en-in/product-support/product/cloud-tiering-appliance/drivers
For CTA/VE and CTA-HA/VE:
https://www.dell.com/support/home/en-in/product-support/product/cloud-tiering-applianceve/drivers
 

Related Information


Article Properties


Affected Product

Product Security Information

Last Published Date

11 Aug 2021

Version

1

Article Type

Dell Security Advisory