DSA-2021-295: Dell EMC PowerStore Family Security Update for Apache Log4j Remote Code Execution Vulnerability (CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, CVE-2021-44832, and CVE-2022-23307)

Oversigt: Dell EMC PowerStore Family remediation is available for the Apache Log4j Remote Code Execution Vulnerability that may be exploited by malicious users to compromise the affected system. Dell recommends implementing this remediation as soon as possible in light of the critical severity of the vulnerability. ...

Denne artikel gælder for Denne artikel gælder ikke for Denne artikel er ikke knyttet til et bestemt produkt. Det er ikke alle produktversioner, der er identificeret i denne artikel.

Virkning

Critical

Oplysninger

Third-party Component CVEs More information
Apache log4j CVE-2021-44228 Apache Log4j Remote Code Execution
CVE-2021-45046
CVE-2021-45105
CVE-2021-44832
CVE-2022-23307
Third-party Component CVEs More information
Apache log4j CVE-2021-44228 Apache Log4j Remote Code Execution
CVE-2021-45046
CVE-2021-45105
CVE-2021-44832
CVE-2022-23307
Dell Technologies anbefaler, at alle kunder tager hensyn til både CVSS-basisresultatet og alle relevante tidsmæssige og miljømæssige resultater, som kan have betydning for den potentielle alvorsgrad, der er forbundet med en bestemt sikkerhedsrisiko.

Berørte produkter og udbedring

CVEs Addressed Product Affected Versions Updated Versions Link to Update
CVE-2021-44228 Dell EMC PowerStore Family Operating System
 
Versions before 2.0.1.3-1538564 PowerStore T OS Upgrade 2.0.1.3-1538564
PowerStore X OS Upgrade 2.0.1.3-1538564
PowerStore T OS Upgrade 2.1.0.0-1561821
https://www.dell.com/support/home/?app=drivers
CVE-2021-45046
CVE-2021-45105 Dell EMC PowerStore Family Operating System
 
Versions before 2.1.1.0-1649887 PowerStore T OS Upgrade 2.1.1.0-1649887
PowerStore X OS 2.1.1.0-1649887
 
https://www.dell.com/support/home/?app=drivers

See KB article 196367: DSA-2022-014: Dell EMC PowerStore Family Security Update for Multiple Vulnerabilities
CVE-2021-44832
CVE-2022-23307
CVEs Addressed Product Affected Versions Updated Versions Link to Update
CVE-2021-44228 Dell EMC PowerStore Family Operating System
 
Versions before 2.0.1.3-1538564 PowerStore T OS Upgrade 2.0.1.3-1538564
PowerStore X OS Upgrade 2.0.1.3-1538564
PowerStore T OS Upgrade 2.1.0.0-1561821
https://www.dell.com/support/home/?app=drivers
CVE-2021-45046
CVE-2021-45105 Dell EMC PowerStore Family Operating System
 
Versions before 2.1.1.0-1649887 PowerStore T OS Upgrade 2.1.1.0-1649887
PowerStore X OS 2.1.1.0-1649887
 
https://www.dell.com/support/home/?app=drivers

See KB article 196367: DSA-2022-014: Dell EMC PowerStore Family Security Update for Multiple Vulnerabilities
CVE-2021-44832
CVE-2022-23307

Revisionshistorik

RevisionDateDescription
1.02021-12-30Initial Release
2.02022-01-26Updated Affected Products and Remediation section: Affected Versions, Updated Versions, and Link to Update
3.02022-04-20Updated Affected Products and Remediation sections: Updated Versions and Link to Update.

Relaterede oplysninger

Berørte produkter

PowerStore, PowerStore 1000X, PowerStore 1000T, PowerStore 3000X, PowerStore 3000T, PowerStore 5000X, PowerStore 5000T, PowerStore 500T, PowerStore 7000X, PowerStore 7000T, PowerStore 9000X, PowerStore 9000T, Product Security Information
Artikelegenskaber
Artikelnummer: 000194739
Artikeltype: Dell Security Advisory
Senest ændret: 21 apr. 2022
Find svar på dine spørgsmål fra andre Dell-brugere
Supportservices
Kontrollér, om din enhed er dækket af supportservices.