DSA-2021-091: Dell EMC XtremIO Security Update for Multiple Vulnerabilities

요약: Dell EMC XtremIO remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

이 문서는 다음에 적용됩니다. 이 문서는 다음에 적용되지 않습니다. 이 문서는 특정 제품과 관련이 없습니다. 모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.

영향

High

세부 정보

Proprietary Code CVE(s) 

Description 

CVSSBase Score 

CVSS Vector String  

CVE-2021-21549 

Dell EMC XtremIO Versions prior to 6.3.3-8, contain a Cross-Site Request Forgery Vulnerability in XMS. A non-privileged attacker could potentially exploit this vulnerability, leading to a privileged victim application user being tricked into sending state-changing requests to the vulnerable application, causing unintended server operations. 

8.8 

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 

 

Third-Party Component  

 

CVE(s) 

More information 

OpenSSL 

CVE-2020-1971 

See NVD (http://nvd.nist.gov/) for individual scores for each CVE 

Proprietary Code CVE(s) 

Description 

CVSSBase Score 

CVSS Vector String  

CVE-2021-21549 

Dell EMC XtremIO Versions prior to 6.3.3-8, contain a Cross-Site Request Forgery Vulnerability in XMS. A non-privileged attacker could potentially exploit this vulnerability, leading to a privileged victim application user being tricked into sending state-changing requests to the vulnerable application, causing unintended server operations. 

8.8 

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 

 

Third-Party Component  

 

CVE(s) 

More information 

OpenSSL 

CVE-2020-1971 

See NVD (http://nvd.nist.gov/) for individual scores for each CVE 

Dell Technologies는 모든 고객이 CVSS 기본 점수와 관련 임시 및 환경 점수를 모두 고려할 것을 권장합니다. 이 경우 특정 보안 취약성과 관련된 잠재적인 심각도에 영향을 미칠 수 있습니다.

영향을 받는 제품 및 문제 해결

CVE(s) Addressed 

Product 

Affected Version(s) 

Updated Version(s) 

Link to Update 

CVE-2020-1971 

XtremIO X1, XtremIO X2 

XMS versions prior to 6.3.3-8 

XMS 6.3.3-8 

Dell EMC recommends all customers upgrade at the earliest opportunity. Customers can contact Dell EMC support to perform the upgrade. 

CVE-2021-21549 

CVE(s) Addressed 

Product 

Affected Version(s) 

Updated Version(s) 

Link to Update 

CVE-2020-1971 

XtremIO X1, XtremIO X2 

XMS versions prior to 6.3.3-8 

XMS 6.3.3-8 

Dell EMC recommends all customers upgrade at the earliest opportunity. Customers can contact Dell EMC support to perform the upgrade. 

CVE-2021-21549 

해결 방법 및 완화 방안

None

개정 내역

Revision 

Date 

Description 

1.0 

2021-05-13 

Initial Release 

감사의 말

CVE-2021-21549: Dell would like to thank Tomasz Stachowicz for reporting this issue.

관련 정보

해당 제품

XtremIO, Product Security Information, XtremIO Family, XtremIO HW Gen2 400GB, XtremIO HW Gen2 400GB Encrypt Capbl, XtremIO HW Gen2 400GB Encrypt Disable, XtremIO HW Gen2 400GB Exp Encrypt Disable, XtremIO HW Gen2 400GB Expandable , XtremIO HW Gen2 800GB Encrypt Capbl ...

제품

XtremIO HW Gen2 800GB Encrypt Disable, XtremIO HW Gen3 40TB, XtremIO HW Gen3 40TB Encrypt Disable, XtremIO HW X2-R, XtremIO HW X2-R Encrypt Disable, XtremIO HW X2-S, XtremIO HW X2-S Encrypt Disable, XtremIO HW X2-T, XtremIO HW X2-T Encrypt Disable , XtremIO X1, XtremIO X2 ...
문서 속성
문서 번호: 000186363
문서 유형: Dell Security Advisory
마지막 수정 시간: 18 9월 2025
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.