DSA-2023-058: Dell NetWorker Security Update for Version Disclosure Vulnerability

Zusammenfassung: Dell NetWorker remediation is available for multiple version disclosure security vulnerabilities that may be exploited by malicious users to compromise the affected system.

Dieser Artikel gilt für Dieser Artikel gilt nicht für Dieser Artikel ist nicht an ein bestimmtes Produkt gebunden. In diesem Artikel werden nicht alle Produktversionen aufgeführt.

Auswirkungen

High

Details

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String

CVE-2023-25544
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks. 7.5
High
 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE-2023-24567 Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks. 7.5
High
 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String

CVE-2023-25544
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks. 7.5
High
 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE-2023-24567 Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks. 7.5
High
 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Dell Technologies empfiehlt allen Kunden, sowohl die CVSS-Gesamtbewertung als auch alle relevanten zeitlichen und umweltbezogenen Bewertungen zu berücksichtigen, die sich auf den potenziellen Schweregrad einer bestimmten Sicherheitsschwachstelle auswirken können.

Betroffene Produkte und Korrektur

CVEs Addressed Product Affected Versions Updated Versions Applicable platforms Link to Update
CVE-2023-25544 Dell NetWorker,
NVE
19.5 and earlier versions 19.6 and later versions Windows,
Linux (CentOS, OEL, SuSE, Red Hat Enterprise Linux, Debian, Ubuntu, Fedora)
https://www.dell.com/support/home/en-ca/product-support/product/networker/drivers
 
CVE-2023-24567
 
NOTE: Impacted components: NetWorker AuthC, NetWorker Server.
CVEs Addressed Product Affected Versions Updated Versions Applicable platforms Link to Update
CVE-2023-25544 Dell NetWorker,
NVE
19.5 and earlier versions 19.6 and later versions Windows,
Linux (CentOS, OEL, SuSE, Red Hat Enterprise Linux, Debian, Ubuntu, Fedora)
https://www.dell.com/support/home/en-ca/product-support/product/networker/drivers
 
CVE-2023-24567
 
NOTE: Impacted components: NetWorker AuthC, NetWorker Server.

Revisionsverlauf

RevisionDateDescription
1.02023-03-01Initial Release

Zugehörige Informationen

Betroffene Produkte

NetWorker Family, NetWorker, NetWorker Series, NetWorker Module, Product Security Information
Artikeleigenschaften
Artikelnummer: 000210471
Artikeltyp: Dell Security Advisory
Zuletzt geändert: 09 Sept. 2025
Antworten auf Ihre Fragen erhalten Sie von anderen Dell NutzerInnen
Support Services
Prüfen Sie, ob Ihr Gerät durch Support Services abgedeckt ist.