DSA-2021-186: PowerPath Windows Security Update for OpenSSL_Configuration Utility Vulnerabilities
Shrnutí: OpenSSL_Configuration Utility for PowerPath Windows contains remediation for SM2 Decryption Buffer Overflow and Read buffer overruns processing ASN.1 strings vulnerabilities that could be exploited by malicious users to compromise the affected systems. OpenSSL is being used for communication between PowerPath Windows host and Management server. OpenSSL is not bundled in PowerPath Windows package. However, separate compiled OpenSSL libraries are provided to customers through Dell EMC download site along with an installation script so that customers can install them separately. As vulnerability has been disclosed in the OpenSSL versions, as a remediation PowerPath engineering will update the download site with the latest OpenSSL libraries. ...
Tento článek se vztahuje na
Tento článek se nevztahuje na
Tento článek není vázán na žádný konkrétní produkt.
V tomto článku nejsou uvedeny všechny verze produktu.
Vliv
High
Podrobnosti
| Third-Party Component |
CVE(s) | More information |
| Third-Party Component | CVE-2021-3711 | https://nvd.nist.gov/vuln/detail/CVE-2021-3711 |
| Third-Party Component | CVE-2021-3712 | https://nvd.nist.gov/vuln/detail/CVE-2021-3712 |
| Third-Party Component |
CVE(s) | More information |
| Third-Party Component | CVE-2021-3711 | https://nvd.nist.gov/vuln/detail/CVE-2021-3711 |
| Third-Party Component | CVE-2021-3712 | https://nvd.nist.gov/vuln/detail/CVE-2021-3712 |
Dotčené produkty a náprava
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
| CVE-2021-3711 | PowerPath Windows |
OpenSSL_Configuration Utility | OpenSSL_Configuration Utility 2.0 | https://www.dell.com/support/home/en-in/product-support/product/powerpath-for-windows/drivers |
| CVE-2021-3712 | PowerPath Windows |
OpenSSL_Configuration Utility | OpenSSL_Configuration Utility 2.0 | https://www.dell.com/support/home/en-in/product-support/product/powerpath-for-windows/drivers |
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
| CVE-2021-3711 | PowerPath Windows |
OpenSSL_Configuration Utility | OpenSSL_Configuration Utility 2.0 | https://www.dell.com/support/home/en-in/product-support/product/powerpath-for-windows/drivers |
| CVE-2021-3712 | PowerPath Windows |
OpenSSL_Configuration Utility | OpenSSL_Configuration Utility 2.0 | https://www.dell.com/support/home/en-in/product-support/product/powerpath-for-windows/drivers |
Zástupná řešení a opatření pro zmírnění rizik
None
Historie změn
| Revision | Date | Description |
| 1.0 | 2021-09-16 | Initial Release |
Související informace
Právní upozornění
Dotčené produkty
Product Security InformationVlastnosti článku
Číslo článku: 000191543
Typ článku: Dell Security Advisory
Poslední úprava: 21 Nov 2025
Najděte odpovědi na své otázky od ostatních uživatelů společnosti Dell
Služby podpory
Zkontrolujte, zda se na vaše zařízení vztahují služby podpory.