DSA-2024-102: Security Update for Dell Technologies PowerProtect DD Vulnerabilities
Summary: Dell Technologies PowerProtect DD remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
High
Details
| Third-party Component |
CVEs |
More Information |
|---|---|---|
| libxml2 |
CVE-2023-29469, CVE-2023-28484, CVE-2022-40304, CVE-2022-40303 |
See NVD link below for individual scores for each CVE. |
| python-wheel |
CVE-2022-40898 |
See NVD link below for individual scores for each CVE. |
| cloud-init |
CVE-2023-1786 |
See NVD link below for individual scores for each CVE. |
| python-certifi |
CVE-2022-23491 |
See NVD link below for individual scores for each CVE. |
| OpenSSL |
CVE-2022-4304 |
See NVD link below for individual scores for each CVE. |
| net-snmp |
CVE-2022-44793, CVE-2020-15862, CVE-2020-15861, CVE-2019-20892, CVE-2015-8100 |
See NVD link below for individual scores for each CVE. |
Affected Products & Remediation
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| Dell PowerProtect DD series appliances | DD OS | Versions 7.0 through 7.12 | Version 7.13.0.20 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| Dell PowerProtect DD series appliances | DD OS LTS 2023 7.10 | Versions 7.10.1.0 through 7.10.1.15 | Version 7.10.1.20 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| Dell PowerProtect DD series appliances | DD OS LTS 2022 7.7 | Versions 7.7.5.1 through 7.7.5.25 | Version 7.7.5.30 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| Dell PowerProtect DD Virtual Edition | DD OS | Versions 7.0 through 7.12 | Version 7.13.0.20 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| Dell PowerProtect DD Virtual Edition | DD OS LTS 2023 7.10 | Versions 7.10.1.0 through 7.10.1.15 | Version 7.10.1.20 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| Dell PowerProtect DD Virtual Edition | DD OS LTS 2022 7.7 | Versions 7.7.5.1 through 7.7.5.25 | Version 7.7.5.30 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| Dell APEX Protection Storage | DD OS | Versions 7.0 through 7.12 | Version 7.13.0.20 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| Dell APEX Protection Storage | DD OS LTS 2023 7.10 | Versions 7.10.1.0 through 7.10.1.15 | Version 7.10.1.20 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| Dell APEX Protection Storage | DD OS LTS 2022 7.7 | Versions 7.7.5.1 through 7.7.5.25 | Version 7.7.5.30 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| PowerProtect DP Series Appliance - IDPA (Integrated Data Protection Appliance): All Models | PowerProtect Data Protection Software | Versions prior to 2.7.6 | Version 2.7.6 or later, DD OS 7.10.1.20 | PowerProtect DP Series Appliance IDPA Drivers & Downloads Data Domain: DD OS Software Versions KB Article for more details about DDOS versions available for download. (Dell Support requires log in to view article.) |
| PowerProtect Data Manager Appliance model: DM5500 | DD OS | Versions prior to 5.15.0.0 | Version 5.15.0.0 or later | Link to download (requires log in to Dell Support) |
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| Dell PowerProtect DD series appliances | DD OS | Versions 7.0 through 7.12 | Version 7.13.0.20 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| Dell PowerProtect DD series appliances | DD OS LTS 2023 7.10 | Versions 7.10.1.0 through 7.10.1.15 | Version 7.10.1.20 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| Dell PowerProtect DD series appliances | DD OS LTS 2022 7.7 | Versions 7.7.5.1 through 7.7.5.25 | Version 7.7.5.30 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| Dell PowerProtect DD Virtual Edition | DD OS | Versions 7.0 through 7.12 | Version 7.13.0.20 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| Dell PowerProtect DD Virtual Edition | DD OS LTS 2023 7.10 | Versions 7.10.1.0 through 7.10.1.15 | Version 7.10.1.20 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| Dell PowerProtect DD Virtual Edition | DD OS LTS 2022 7.7 | Versions 7.7.5.1 through 7.7.5.25 | Version 7.7.5.30 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| Dell APEX Protection Storage | DD OS | Versions 7.0 through 7.12 | Version 7.13.0.20 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| Dell APEX Protection Storage | DD OS LTS 2023 7.10 | Versions 7.10.1.0 through 7.10.1.15 | Version 7.10.1.20 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| Dell APEX Protection Storage | DD OS LTS 2022 7.7 | Versions 7.7.5.1 through 7.7.5.25 | Version 7.7.5.30 or later | See link for more details about DDOS versions available for download (requires log in to Dell Support to view article) |
| PowerProtect DP Series Appliance - IDPA (Integrated Data Protection Appliance): All Models | PowerProtect Data Protection Software | Versions prior to 2.7.6 | Version 2.7.6 or later, DD OS 7.10.1.20 | PowerProtect DP Series Appliance IDPA Drivers & Downloads Data Domain: DD OS Software Versions KB Article for more details about DDOS versions available for download. (Dell Support requires log in to view article.) |
| PowerProtect Data Manager Appliance model: DM5500 | DD OS | Versions prior to 5.15.0.0 | Version 5.15.0.0 or later | Link to download (requires log in to Dell Support) |
For more details about DDOS versions available for download, see the links below (requires log in to Dell Support to view articles):
Please also see:
Workarounds & Mitigations
None
Revision History
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2024-03-19 | Initial Release |
| 2.0 | 2024-03-21 | Updated "Affected Product" section under "Article Properties" |
| 3.0 | 2024-04-15 | Updated wording for a uniform reading |
| 4.0 | 2024-05-22 | Updated the Affected Products and Remediation section: PowerProtect DP Series Appliance - IDPA (Integrated Data Protection Appliance): All Models Remediated Versions and update link |
| 5.0 | 2024-10-11 | Updated CVE Identifier and Third Party Components sections to include the following component and associated CVE IDs: net-snmp |
| 6.0 | 2024-12-12 | Updated Additional Info section to remove IDPA update details; information previously added to the Affected Products and Remediation table on 2024-05-22. No update to content. |