DSA-2024-398: Dell PowerStore Family Security Update for Multiple Vulnerabilities

Samenvatting: Dell PowerStore Family remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.

Dit artikel is van toepassing op Dit artikel is niet van toepassing op Dit artikel is niet gebonden aan een specifiek product. Niet alle productversies worden in dit artikel vermeld.

Impact

High

Gegevens

Third-party Component CVEs More Information
cpio CVE-2023-7207 See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
docker CVE-2024-23651, CVE-2024-23653, CVE-2024-23652 See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
gnutls          CVE-2024-0553,  CVE-2023-5981 See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
kernel CVE-2024-26840, CVE-2021-47113, CVE-2021-47131, CVE-2024-26852, CVE-2021-46955, CVE-2024-26862, CVE-2024-0639, CVE-2024-27043, CVE-2022-48631, CVE-2024-23307, CVE-2022-48651, CVE-2024-26816, CVE-2024-26906, CVE-2024-26689, CVE-2021-47041, CVE-2021-47074, CVE-2024-26744 See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
krb5 CVE-2024-26458, CVE-2024-26461

See NVD link below for individual scores for each CVE.

http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

less CVE-2024-32487

See NVD link below for individual scores for each CVE.

http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

libssh  CVE-2020-1730,  CVE-2023-6918,  CVE-2023-1667,  CVE-2023-48795,  CVE-2023-6004,  CVE-2020-16135,  CVE-2019-14889,  CVE-2023-2283,  CVE-2021-3634

See NVD link below for individual scores for each CVE.

http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

libxml2 CVE-2024-25062

See NVD link below for individual scores for each CVE.

http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

nghttp2 CVE-2024-28182

See NVD link below for individual scores for each CVE.

http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

nss  CVE-2023-5388

See NVD link below for individual scores for each CVE.

http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

OpenJDK CVE-2024-20952, CVE-2024-20918, CVE-2024-20921, CVE-2024-20919, CVE-2024-20926, CVE-2024-20945, CVE-2024-21094, CVE-2024-21012, CVE-2024-21068, CVE-2024-21011, CVE-2024-21085, CVE-2024-20952, CVE-2024-20918, CVE-2024-20921, CVE-2024-20919, CVE-2024-20926, CVE-2024-20945, CVE-2024-21094, CVE-2024-21012, CVE-2024-21068, CVE-2024-21011, CVE-2024-21085, CVE-2024-20952, CVE-2024-20918, CVE-2024-20921, CVE-2024-20919, CVE-2024-20926

See NVD link below for individual scores for each CVE.

http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

OpenSSH  CVE-2023-51385 See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
pam CVE-2024-22365 See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
perl  CVE-2018-6913, CVE-2017-6512, CVE-2018-6798, CVE-2023-31484 See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
postgresql  CVE-2024-0985 See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
Python3  CVE-2023-52425,  CVE-2024-0450 See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
runc CVE-2024-21626 See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
sudo        CVE-2023-42465 See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
suse-module-tools  CVE-2023-1829,  CVE-2023-23559 See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
util-linux CVE-2024-28085 See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
vim CVE-2023-4733, CVE-2023-4738, CVE-2023-4781, CVE-2023-5535, CVE-2023-4750, CVE-2023-4752 See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
xen-libs          CVE-2023-46839  See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2024-42429 Dell PowerStore contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized access and modification of application data" 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2024-42429 Dell PowerStore contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized access and modification of application data" 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies raadt aan dat alle klanten rekening houden met zowel de basisscore van CVSS als alle relevante tijdelijke en omgevingsscores die gevolgen kunnen hebben voor de mogelijke ernst van de specifieke beveiligingsproblemen.

Getroffen producten en herstel

Product Software/Firmware Affected Versions Remediated Versions Link
PowerStore 500T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/en-us/product-support/product/powerstore-500t/drivers
PowerStore 1000T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-1000t/drivers
PowerStore 1200T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-1200t/drivers
PowerStore 3000T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-3000t/drivers
PowerStore 3200T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-3200t/drivers
PowerStore 5000T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-5000t/drivers
PowerStore 5200T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-5200t/drivers
PowerStore 7000T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-7000t/drivers
PowerStore 9000T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-9000t/drivers
PowerStore 9200T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-9200t/drivers
Product Software/Firmware Affected Versions Remediated Versions Link
PowerStore 500T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/en-us/product-support/product/powerstore-500t/drivers
PowerStore 1000T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-1000t/drivers
PowerStore 1200T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-1200t/drivers
PowerStore 3000T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-3000t/drivers
PowerStore 3200T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-3200t/drivers
PowerStore 5000T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-5000t/drivers
PowerStore 5200T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-5200t/drivers
PowerStore 7000T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-7000t/drivers
PowerStore 9000T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-9000t/drivers
PowerStore 9200T PowerStoreT OS Versions prior to 4.0.0.2-2365061-retail Version 4.0.0.2-2365061-retail or later https://www.dell.com/support/home/product-support/product/powerstore-9200t/drivers

Revisiegeschiedenis

 

RevisionDateDescription
1.02024-09-16Initial Release
2.02024-10-07Removed unnecessary embedded links
3.02024-12-18Updated for enhanced presentation with no changes to content

Verwante informatie

Getroffen producten

PowerStore, PowerStore 1000T, PowerStore 1200T, PowerStore 3000T, PowerStore 3200T, PowerStore 5000T, PowerStore 500T, PowerStore 5200T, PowerStore 7000T, PowerStore 9000T, PowerStore 9200T, PowerStoreOS
Artikeleigenschappen
Artikelnummer: 000228610
Artikeltype: Dell Security Advisory
Laatst aangepast: 18 dec. 2024
Vind antwoorden op uw vragen via andere Dell gebruikers
Support Services
Controleer of uw apparaat wordt gedekt door Support Services.