DSA-2021-125: Dell EMC NetWorker Security Update for Multiple Vulnerabilities
Riepilogo: Dell EMC NetWorker remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.
Questo articolo si applica a
Questo articolo non si applica a
Questo articolo non è legato a un prodotto specifico.
Non tutte le versioni del prodotto sono identificate in questo articolo.
Impatto
Medium
Dettagli
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2021-21600 | Dell NetWorker 19.4 or earlier contains an uncontrolled resource consumption flaw in its API service. An authorized API user may potentially exploit this vulnerability using the web and desktop user interfaces, leading to denial of service in the manageability path. | 6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| Third-Party Component | CVEs | More Information |
| OpenSSL | CVE-2020-1971 | See NVD (http://nvd.nist.gov/) for individual scores for each CVE. |
| Apache Tomcat | CVE-2020-1935 | |
| CVE-2021-24122 |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2021-21600 | Dell NetWorker 19.4 or earlier contains an uncontrolled resource consumption flaw in its API service. An authorized API user may potentially exploit this vulnerability using the web and desktop user interfaces, leading to denial of service in the manageability path. | 6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| Third-Party Component | CVEs | More Information |
| OpenSSL | CVE-2020-1971 | See NVD (http://nvd.nist.gov/) for individual scores for each CVE. |
| Apache Tomcat | CVE-2020-1935 | |
| CVE-2021-24122 |
Prodotti interessati e correzione
| CVEs Addressed | Product | Affected Versions | Updated Versions | Link to Update |
| CVE-2021-21600 | Dell EMC NetWorker | 18.x, 19.1.x, 19.2.x 19.3.x, and 19.4.x prior to 19.4.0.4. |
|
https://www.dell.com/support/home/en-in/product-support/product/networker/drivers |
| CVE-2020-1971 | 18.x, 19.1.x, 19.2.x 19.3.x, and 19.4.x. | 19.5.0 and later. | ||
| CVE-2020-1935 | ||||
| CVE-2021-24122 |
| CVEs Addressed | Product | Affected Versions | Updated Versions | Link to Update |
| CVE-2021-21600 | Dell EMC NetWorker | 18.x, 19.1.x, 19.2.x 19.3.x, and 19.4.x prior to 19.4.0.4. |
|
https://www.dell.com/support/home/en-in/product-support/product/networker/drivers |
| CVE-2020-1971 | 18.x, 19.1.x, 19.2.x 19.3.x, and 19.4.x. | 19.5.0 and later. | ||
| CVE-2020-1935 | ||||
| CVE-2021-24122 |
Cronologia delle revisioni
| Revision | Date | Description |
| 1.0 | 2021-07-20 | Initial Release |
| 1.1 | 2021-09-02 | Updated "Affected Products and Remediation" Section |
Ringraziamenti
CVE-2021-21600: Dell Technologies would like to thank J-M Roth for reporting this issue.
Informazioni correlate
Dichiarazione di non responsabilità
Prodotti interessati
NetWorker, Product Security InformationProprietà dell'articolo
Numero articolo: 000189694
Tipo di articolo: Dell Security Advisory
Ultima modifica: 02 set 2021
Trova risposta alle tue domande dagli altri utenti Dell
Support Services
Verifica che il dispositivo sia coperto dai Servizi di supporto.