DSA-2022-182: Cloud Mobility for Dell Storage Security Update for a Path Traversal RCE Vulnerability
Zusammenfassung: Cloud Mobility for Dell Storage remediation is available for a path traversal RCE vulnerability that may be exploited by malicious users to compromise the affected system.
Dieser Artikel gilt für
Dieser Artikel gilt nicht für
Dieser Artikel ist nicht an ein bestimmtes Produkt gebunden.
In diesem Artikel werden nicht alle Produktversionen aufgeführt.
Auswirkungen
High
Details
Cloud Mobility for Dell Storage 1.3.0 contains an RCE vulnerability. A nonprivileged user could potentially exploit this vulnerability, leading to achieving a root shell. This is a high severity issue; so Dell Technologies recommends customers to upgrade at the earliest opportunity.
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector |
| CVE-2022-33936 | Cloud Mobility for Dell Storage versions 1.3.0 and earlier contains a path traversal in the backup mechanism for the vApp. Any basic user may purposefully or accidentally exploit this vulnerability, leading to RCE with full take over of the system. | 8.0 | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Cloud Mobility for Dell Storage 1.3.0 contains an RCE vulnerability. A nonprivileged user could potentially exploit this vulnerability, leading to achieving a root shell. This is a high severity issue; so Dell Technologies recommends customers to upgrade at the earliest opportunity.
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector |
| CVE-2022-33936 | Cloud Mobility for Dell Storage versions 1.3.0 and earlier contains a path traversal in the backup mechanism for the vApp. Any basic user may purposefully or accidentally exploit this vulnerability, leading to RCE with full take over of the system. | 8.0 | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Betroffene Produkte und Korrektur
| CVE Addressed | Product | Affected Version | Updated Version | Link to Update |
| CVE-2022-33936 | Cloud Mobility for Dell Storage | 1.3.0 | 1.3.1 | Amazon Marketplace: Cloud Mobility for Dell Storage Or VMware Marketplace |
| CVE Addressed | Product | Affected Version | Updated Version | Link to Update |
| CVE-2022-33936 | Cloud Mobility for Dell Storage | 1.3.0 | 1.3.1 | Amazon Marketplace: Cloud Mobility for Dell Storage Or VMware Marketplace |
Workarounds und Korrekturmaßnahmen
We now reject any patterns in the restore tar file that start with an absolute path or contain .. anywhere in the file path.
Revisionsverlauf
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2022-07-06 | Initial release |
Zugehörige Informationen
Rechtlicher Hinweis
Betroffene Produkte
Product Security InformationArtikeleigenschaften
Artikelnummer: 000201258
Artikeltyp: Dell Security Advisory
Zuletzt geändert: 20 Juni 2023
Antworten auf Ihre Fragen erhalten Sie von anderen Dell NutzerInnen
Support Services
Prüfen Sie, ob Ihr Gerät durch Support Services abgedeckt ist.