DSA-2022-183: Dell GeoDrive Security Update for Multiple Vulnerabilities

요약: Dell GeoDrive 2.2-P3 remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.

이 문서는 다음에 적용됩니다. 이 문서는 다음에 적용되지 않습니다. 이 문서는 특정 제품과 관련이 없습니다. 모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.

영향

High

세부 정보

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2022-33919 Dell GeoDrive, versions 2.1 - 2.2 contain an information disclosure vulnerability in UI. An authenticated nonadmin user may potentially exploit this vulnerability and view sensitive information. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2022-33920 Dell GeoDrive versions before 2.2 contain Unquoted File Path Vulnerabilities. A low privilege attacker may potentially exploit this vulnerability, leading to execution of arbitrary code in the SYSTEM security context. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2022-33937 Dell GeoDrive versions before 2.2 contain a Path Traversal Vulnerability in the reporting function. A local, low privileged attacker may potentially exploit this vulnerability, to gain unauthorized delete access to the files stored on the server file system, with the privileges of the GeoDrive service: NT AUTHORITY\SYSTEM 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVE-2022-33921 Dell GeoDrive versions before 2.2 contain Multiple DLL Hijacking Vulnerabilities. A low privilege attacker may potentially exploit this vulnerability, leading to execution of arbitrary code in the SYSTEM security context. 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2022-33922 Dell GeoDrive versions before 2.2 contains Insecure File and Folder Permissions vulnerabilities. A low privilege attacker may potentially exploit this vulnerability, leading to the execution of arbitrary code in the SYSTEM security context. Dell Technologies recommends customers to upgrade at the earliest opportunity. 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2022-33918 Dell GeoDrive versions 2.1 - 2.2 contain an information disclosure vulnerability. An authenticated nonadmin user may potentially exploit this vulnerability and gain access to sensitive information. 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2022-33919 Dell GeoDrive, versions 2.1 - 2.2 contain an information disclosure vulnerability in UI. An authenticated nonadmin user may potentially exploit this vulnerability and view sensitive information. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2022-33920 Dell GeoDrive versions before 2.2 contain Unquoted File Path Vulnerabilities. A low privilege attacker may potentially exploit this vulnerability, leading to execution of arbitrary code in the SYSTEM security context. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2022-33937 Dell GeoDrive versions before 2.2 contain a Path Traversal Vulnerability in the reporting function. A local, low privileged attacker may potentially exploit this vulnerability, to gain unauthorized delete access to the files stored on the server file system, with the privileges of the GeoDrive service: NT AUTHORITY\SYSTEM 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVE-2022-33921 Dell GeoDrive versions before 2.2 contain Multiple DLL Hijacking Vulnerabilities. A low privilege attacker may potentially exploit this vulnerability, leading to execution of arbitrary code in the SYSTEM security context. 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2022-33922 Dell GeoDrive versions before 2.2 contains Insecure File and Folder Permissions vulnerabilities. A low privilege attacker may potentially exploit this vulnerability, leading to the execution of arbitrary code in the SYSTEM security context. Dell Technologies recommends customers to upgrade at the earliest opportunity. 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2022-33918 Dell GeoDrive versions 2.1 - 2.2 contain an information disclosure vulnerability. An authenticated nonadmin user may potentially exploit this vulnerability and gain access to sensitive information. 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Dell Technologies는 모든 고객이 CVSS 기본 점수와 관련 임시 및 환경 점수를 모두 고려할 것을 권장합니다. 이 경우 특정 보안 취약성과 관련된 잠재적인 심각도에 영향을 미칠 수 있습니다.

영향을 받는 제품 및 문제 해결

Product Affected Versions Updated Versions Link to Update
Dell GeoDrive GeoDrive versions before 2.2-P2  GeoDrive 2.2-P3 https://www.dell.com/support/home/product-support/product/atmos-geodrive-for-windows/drivers
 
Product Affected Versions Updated Versions Link to Update
Dell GeoDrive GeoDrive versions before 2.2-P2  GeoDrive 2.2-P3 https://www.dell.com/support/home/product-support/product/atmos-geodrive-for-windows/drivers
 

개정 내역

RevisionDateDescription
1.02022-09-22Initial Release

관련 정보

해당 제품

Product Security Information
문서 속성
문서 번호: 000203632
문서 유형: Dell Security Advisory
마지막 수정 시간: 22 9월 2022
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.