Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

DSA-2020-123: Dell EMC Server Platform Security Advisory for Intel SA-00329 – Intel® Processors Data Leakage Advisory

Summary: Dell EMC Server Platform Security Advisory for Intel SA-00329 – Intel® Processors Data Leakage Advisory - CVE-2020-0548, CVE-2020-0549

This article may have been automatically translated. If you have any feedback regarding its quality, please let us know using the form at the bottom of this page.

Article Content


Symptoms

DSA ID: DSA-2020-123

CVE Identifier: CVE-2020-0548, CVE-2020-0549

Severity: Medium

Severity Rating: CVSSv3 Base Score: See NVD (http://nvd.nist.gov/) for individual scores for each CVE
                        
Affected products:
Dell EMC Servers (see Resolution section below for complete list of affected products)

Summary
Dell EMC Servers require a security update to address Intel vulnerabilities. 

Details
Updates are available to address the following security vulnerabilities.

Intel-SA-00329: Intel® Processors Data Leakage Advisory

  • CVE-2020-0548: Mitigations are provided with these BIOS updates. Dell expects to work together with its ecosystem partner to further strengthen mitigations in a subsequent BIOS update.
  • CVE-2020-0549: Mitigations are provided with these BIOS updates.

Customers should also review their OS vendor’s Security Advisory for information, to ensure appropriate vulnerability identification and patch/configuration measures to be used in conjunction with the updates provided by Dell for the most effective mitigation.

For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm. To search for a particular CVE, use the database’s search utility at http://web.nvd.nist.gov/view/vuln/search.

Resolution
The following is a list of impacted products and expected release dates. Dell recommends all customers update at the earliest opportunity.

We encourage customers to review Intel’s Security Advisory for information, including appropriate identification and mitigation measures.

Please visit the Drivers and Downloads site for updates on the applicable products. Note, the following list of impacted products with released BIOS updates are linked. To learn more, visit the Dell Knowledge Base article Dell Updating Firmware using Dell Update Packages (DUP’s), and download the update for your Dell computer.  The described Dell notification solutions provide options for the automatic notification and download of the driver, BIOS, and firmware updates once available.


Dell EMC Server Products Affected

 

Product

BIOS Update Version (or greater)

Release Date / Expected Release Date
(MM/DD/YYYY)

R640, R740, R740XD, R940, NX3240, NX3340 2.7.7 07/14/2020
XC740XD, XC640, XC940 To be provided upon release August 2020
R540, R440, T440, XR2 2.7.7 07/14/2020
R740XD2 2.7.7 07/14/2020
R840, R940XA 2.7.7 07/14/2020
T640 2.7.7 07/14/2020
C6420, XC6420 2.7.7 07/14/2020
FC640, M640, M640P 2.7.7 07/14/2020
MX740C 2.7.7 07/14/2020
MX840C 2.7.7 07/14/2020
C4140 2.7.7 07/14/2020
T140, T340, R240, R340, NX440 2.3.5 07/14/2020
T130, T330, R230, R330, NX430 2.10.1 06/29/2020
DSS9600, DSS9620, DSS9630 2.6.3 04/15/2020

 

Legal Information

Read and use the information in this Dell EMC Security Advisory to assist in avoiding a situation that might arise from the problems described herein. If you have any questions regarding this advisory, contact Dell EMC Technical Support (https://www.dell.com/support/contents/category/contact-information). Dell EMC distributes Dell EMC Security Advisories, in order to bring to the attention of users of the affected Dell EMC products, important security information. Dell EMC recommends that all users determine the applicability of this information to their individual situations and take appropriate action. The information set forth herein is provided "as is" without warranty of any kind. Dell EMC disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event, shall Dell EMC or its suppliers, be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Dell EMC or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply.

Cause

 

Resolution

 

Article Properties


Affected Product
Hyper-converged Systems, VxRail, XC Series Appliances, PowerEdge, Dell EMC Microsoft Storage Spaces Direct Ready Nodes, VxFlex Ready Nodes, Dell EMC vSAN Ready Nodes, PowerFlex Appliance, NX Series, Poweredge C4140, PowerEdge C6420, PowerEdge FC640 , PowerEdge M640, PowerEdge M640 (for PE VRTX), PowerEdge MX740C, PowerEdge R230, PowerEdge R240, PowerEdge R330, PowerEdge R340, PowerEdge R640, PowerEdge R740, PowerEdge R740XD, PowerEdge R740XD2, PowerEdge R840, PowerEdge R940, PowerEdge T130, PowerEdge T140, PowerEdge T330, PowerEdge T340, PowerEdge T640 ...
Last Published Date

29 Jul 2022

Version

3

Article Type

Solution