Dieser Artikel gilt für Dieser Artikel gilt nicht für Dieser Artikel ist nicht an ein bestimmtes Produkt gebunden. In diesem Artikel werden nicht alle Produktversionen aufgeführt.

Auswirkungen

High

Details

   Summary:     
Dell EMC Unity contains fixes for multiple security vulnerabilities that may potentially be exploited by malicious users to compromise the affected system.

The components are updated for the following vulnerabilities:    

  • Improper Authorization Vulnerability

CVE-2019-3734

Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain an improper authorization vulnerability in NAS Server quotas configuration. A remote authenticated Unisphere Operator may potentially exploit this vulnerability to edit quota configuration of other users. 

CVSS v3 Base Score: 5.4 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L)

  • Plain-text Password Storage Vulnerability

CVE-2019-3741

Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain a plain-text password storage vulnerability. A Unisphere user s (including the admin privilege user) password is stored in a plain text in Unity Data Collection bundle (logs files for troubleshooting). A local authenticated attacker with access to the Data Collection bundle may use the exposed password to gain access with the privileges of the compromised user.

CVSS v3 Base Score: 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

The components are updated for the following vulnerabilities:    

  • Improper Authorization Vulnerability

CVE-2019-3734

Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain an improper authorization vulnerability in NAS Server quotas configuration. A remote authenticated Unisphere Operator may potentially exploit this vulnerability to edit quota configuration of other users. 

CVSS v3 Base Score: 5.4 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L)

  • Plain-text Password Storage Vulnerability

CVE-2019-3741

Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain a plain-text password storage vulnerability. A Unisphere user s (including the admin privilege user) password is stored in a plain text in Unity Data Collection bundle (logs files for troubleshooting). A local authenticated attacker with access to the Data Collection bundle may use the exposed password to gain access with the privileges of the compromised user.

CVSS v3 Base Score: 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Dell Technologies empfiehlt allen Kunden, sowohl die CVSS-Gesamtbewertung als auch alle relevanten zeitlichen und umweltbezogenen Bewertungen zu berücksichtigen, die sich auf den potenziellen Schweregrad einer bestimmten Sicherheitsschwachstelle auswirken können.

Betroffene Produkte und Korrektur

Affected products:     

  • Dell EMC Unity Operating Environment (OE) versions prior to 5.0.0.0.5.116

  • Dell EMC UnityVSA Operating Environment (OE) versions prior to 5.0.0.0.5.116
     

Remediation:     
The following Dell EMC Unity releases address these vulnerabilities:     

  • Dell EMC Unity Operating Environment (OE) version 5.0.0.0.5.116

  • Dell EMC UnityVSA Operating Environment (OE) versions 5.0.0.0.5.116

Dell EMC recommends all customers upgrade at the earliest opportunity.

Customers can refer to Dell EMC target code information at https://support.emc.com/docu39695_Target_Revisions_and_Adoption_Rates.pdf?language=en_US&language=en_US.


Link to Remedies:      
Registered Dell EMC Support customers can download Dell EMC Unity software from the Dell EMC Online Support web site at https://support.emc.com/downloads/39949_Dell-EMC-Unity-Family



Affected products:     

  • Dell EMC Unity Operating Environment (OE) versions prior to 5.0.0.0.5.116

  • Dell EMC UnityVSA Operating Environment (OE) versions prior to 5.0.0.0.5.116
     

Remediation:     
The following Dell EMC Unity releases address these vulnerabilities:     

  • Dell EMC Unity Operating Environment (OE) version 5.0.0.0.5.116

  • Dell EMC UnityVSA Operating Environment (OE) versions 5.0.0.0.5.116

Dell EMC recommends all customers upgrade at the earliest opportunity.

Customers can refer to Dell EMC target code information at https://support.emc.com/docu39695_Target_Revisions_and_Adoption_Rates.pdf?language=en_US&language=en_US.


Link to Remedies:      
Registered Dell EMC Support customers can download Dell EMC Unity software from the Dell EMC Online Support web site at https://support.emc.com/downloads/39949_Dell-EMC-Unity-Family



Zugehörige Informationen

Betroffene Produkte

Dell EMC Unity Family

Produkte

Product Security Information, Dell Unity 300, Dell EMC Unity 300F, Dell EMC Unity 350F, Dell EMC Unity XT 380, Dell EMC Unity XT 380F, Dell EMC Unity 400, Dell EMC Unity 400F, Dell EMC Unity 450F, Dell EMC Unity XT 480, Dell EMC Unity XT 480F , Dell EMC Unity 500, Dell EMC Unity 500F, Dell EMC Unity 550F, Dell EMC Unity 600F, Dell EMC Unity 650F, Dell EMC Unity XT 680F, Dell EMC Unity XT 880F, Dell EMC Unity Family |Dell EMC Unity All Flash, Dell EMC Unity Family, Dell EMC Unity Hybrid ...
Artikeleigenschaften
Artikelnummer: 000001846
Artikeltyp: Dell Security Advisory
Zuletzt geändert: 23 Sept. 2024
Antworten auf Ihre Fragen erhalten Sie von anderen Dell NutzerInnen
Support Services
Prüfen Sie, ob Ihr Gerät durch Support Services abgedeckt ist.