DSA-2021-186: PowerPath Windows Security Update for OpenSSL_Configuration Utility Vulnerabilities
Zusammenfassung: OpenSSL_Configuration Utility for PowerPath Windows contains remediation for SM2 Decryption Buffer Overflow and Read buffer overruns processing ASN.1 strings vulnerabilities that could be exploited by malicious users to compromise the affected systems. OpenSSL is being used for communication between PowerPath Windows host and Management server. OpenSSL is not bundled in PowerPath Windows package. However, separate compiled OpenSSL libraries are provided to customers through Dell EMC download site along with an installation script so that customers can install them separately. As vulnerability has been disclosed in the OpenSSL versions, as a remediation PowerPath engineering will update the download site with the latest OpenSSL libraries. ...
Dieser Artikel gilt für
Dieser Artikel gilt nicht für
Dieser Artikel ist nicht an ein bestimmtes Produkt gebunden.
In diesem Artikel werden nicht alle Produktversionen aufgeführt.
Auswirkungen
High
Details
| Third-Party Component |
CVE(s) | More information |
| Third-Party Component | CVE-2021-3711 | https://nvd.nist.gov/vuln/detail/CVE-2021-3711 |
| Third-Party Component | CVE-2021-3712 | https://nvd.nist.gov/vuln/detail/CVE-2021-3712 |
| Third-Party Component |
CVE(s) | More information |
| Third-Party Component | CVE-2021-3711 | https://nvd.nist.gov/vuln/detail/CVE-2021-3711 |
| Third-Party Component | CVE-2021-3712 | https://nvd.nist.gov/vuln/detail/CVE-2021-3712 |
Betroffene Produkte und Korrektur
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
| CVE-2021-3711 | PowerPath Windows |
OpenSSL_Configuration Utility | OpenSSL_Configuration Utility 2.0 | https://www.dell.com/support/home/en-in/product-support/product/powerpath-for-windows/drivers |
| CVE-2021-3712 | PowerPath Windows |
OpenSSL_Configuration Utility | OpenSSL_Configuration Utility 2.0 | https://www.dell.com/support/home/en-in/product-support/product/powerpath-for-windows/drivers |
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
| CVE-2021-3711 | PowerPath Windows |
OpenSSL_Configuration Utility | OpenSSL_Configuration Utility 2.0 | https://www.dell.com/support/home/en-in/product-support/product/powerpath-for-windows/drivers |
| CVE-2021-3712 | PowerPath Windows |
OpenSSL_Configuration Utility | OpenSSL_Configuration Utility 2.0 | https://www.dell.com/support/home/en-in/product-support/product/powerpath-for-windows/drivers |
Workarounds und Korrekturmaßnahmen
None
Revisionsverlauf
| Revision | Date | Description |
| 1.0 | 2021-09-16 | Initial Release |
Zugehörige Informationen
Rechtlicher Hinweis
Betroffene Produkte
Product Security InformationArtikeleigenschaften
Artikelnummer: 000191543
Artikeltyp: Dell Security Advisory
Zuletzt geändert: 21 Nov. 2025
Antworten auf Ihre Fragen erhalten Sie von anderen Dell NutzerInnen
Support Services
Prüfen Sie, ob Ihr Gerät durch Support Services abgedeckt ist.