DSA-2021-293: Dell PowerFlex Appliance Security Update for Apache Log4j Remote Code Execution Vulnerability (CVE-2021-44228, CVE-2021-45046, and CVE-2021-45105)

Shrnutí: Dell PowerFlex Appliance remediation is available for the Apache Log4j Remote Code Execution Vulnerability that may be exploited by malicious users to compromise the affected system. Dell recommends implementing this remediation as soon as possible in light of the critical severity of the vulnerability. ...

Tento článek se vztahuje na Tento článek se nevztahuje na Tento článek není vázán na žádný konkrétní produkt. V tomto článku nejsou uvedeny všechny verze produktu.

Vliv

Critical

Podrobnosti

Third-party Component CVEs More information
Apache Log4j
 
CVE-2021-44228
CVE-2021-45046
CVE-2021-45105
Apache Log4j Remote Code Execution
 
Third-party Component CVEs More information
Apache Log4j
 
CVE-2021-44228
CVE-2021-45046
CVE-2021-45105
Apache Log4j Remote Code Execution
 
Společnost Dell Technologies všem zákazníkům doporučuje vzít v úvahu základní hodnocení CVSS i všechna související hodnocení v daném čase a prostředí, která mohou mít vliv na potenciální závažnost dané konkrétní bezpečnostní hrozby.

Dotčené produkty a náprava

Affected Products and Remediation
CVEs Product Affected Versions Updated Versions Link to Update
CVE-2021-4228 
CVE-2021-45046
 
CVE-2021-45105
 
PowerFlex Appliance
 
 
Versions before Intelligent Catalog 38_356_00_r10
 
 
Intelligent_Catalog_38_356_01_r1 For IC downloads:
https://www.dell.com/support/home/product-support/product/vxflex-appliance-sw/drivers
 
 Versions before Intelligent Catalog 38_362_00_r7 Intelligent_Catalog_38_362_01_r1





Affected Components in the Product
Component Affected Versions Updated Versions Link to update
Dell PowerFlex Presentation Server 3.5, 3.5.1, 3.5.1.1, 3.5.1.2, 3.5.1.3, 3.5.1.4 3.6, 3.6.0.1, and 3.6.0.2 Versions 3.6.0.3 and 3.5.1.5 PowerFlex 3.6.0.3 build 107 Complete Software 
 
 
PowerFlex 3.5.1.5 Build 105 Complete Software Download
 
DSA-2021-272
Dell PowerFlex Manager 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, 3.7.1, 3.7.2, and 3.8.0 Version 3.8.0 (Build Number 3.8.0-8187) For IC downloads:
https://www.dell.com/support/home/product-support/product/vxflex-appliance-sw/drivers
VMware vCenter Server Appliance 6.5, 6.7, and 7.0 VMware-VCSA-all-6.5.0-19261680 (6.5 U3s)

VMware-VCSA-all-6.7 Update 3q (6.7.0 Build19300125

VMware-VCSA-all-7.0 Update 3c Build 19234570
For IC downloads:
https://www.dell.com/support/home/product-support/product/vxflex-appliance-sw/drivers

Affected Products and Remediation
CVEs Product Affected Versions Updated Versions Link to Update
CVE-2021-4228 
CVE-2021-45046
 
CVE-2021-45105
 
PowerFlex Appliance
 
 
Versions before Intelligent Catalog 38_356_00_r10
 
 
Intelligent_Catalog_38_356_01_r1 For IC downloads:
https://www.dell.com/support/home/product-support/product/vxflex-appliance-sw/drivers
 
 Versions before Intelligent Catalog 38_362_00_r7 Intelligent_Catalog_38_362_01_r1





Affected Components in the Product
Component Affected Versions Updated Versions Link to update
Dell PowerFlex Presentation Server 3.5, 3.5.1, 3.5.1.1, 3.5.1.2, 3.5.1.3, 3.5.1.4 3.6, 3.6.0.1, and 3.6.0.2 Versions 3.6.0.3 and 3.5.1.5 PowerFlex 3.6.0.3 build 107 Complete Software 
 
 
PowerFlex 3.5.1.5 Build 105 Complete Software Download
 
DSA-2021-272
Dell PowerFlex Manager 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, 3.7.1, 3.7.2, and 3.8.0 Version 3.8.0 (Build Number 3.8.0-8187) For IC downloads:
https://www.dell.com/support/home/product-support/product/vxflex-appliance-sw/drivers
VMware vCenter Server Appliance 6.5, 6.7, and 7.0 VMware-VCSA-all-6.5.0-19261680 (6.5 U3s)

VMware-VCSA-all-6.7 Update 3q (6.7.0 Build19300125

VMware-VCSA-all-7.0 Update 3c Build 19234570
For IC downloads:
https://www.dell.com/support/home/product-support/product/vxflex-appliance-sw/drivers

Historie změn

RevisionDateDescription
1.02021-12-16Initial Release
1.12021-12-17Added VMware vCenter Server Appliance workaround KB article link.
1.22021-12-22Added CVE-2021-45105 and remediation guidance
1.32022-01-10Added new ZIP with Log4j 2.17.1 remediation
2.02022-02-09Minor update - Workarounds and Mitigations - PowerFlex Manager section
3.02022-02-25Updated Affected Products and Remediation section, added links to update
4.02022-06-01updated VMware vCenter remediation

Související informace

Dotčené produkty

PowerFlex Appliance, PowerFlex appliance R650, PowerFlex appliance R6525, Powerflex appliance R750, Product Security Information, PowerFlex Software, PowerFlex appliance R640, PowerFlex appliance R740XD, PowerFlex appliance R840
Vlastnosti článku
Číslo článku: 000194579
Typ článku: Dell Security Advisory
Poslední úprava: 01 čvn 2022
Najděte odpovědi na své otázky od ostatních uživatelů společnosti Dell
Služby podpory
Zkontrolujte, zda se na vaše zařízení vztahují služby podpory.