DSA-2024-493: Security Update for Dell Enterprise SONiC Distribution Vulnerabilities

Zusammenfassung: Dell Enterprise SONiC remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Dieser Artikel gilt für Dieser Artikel gilt nicht für Dieser Artikel ist nicht an ein bestimmtes Produkt gebunden. In diesem Artikel werden nicht alle Produktversionen aufgeführt.

Auswirkungen

High

Details

Third-party Component

CVEs

More Information

setuptools

CVE-2022-40897, CVE-2024-6345

See NVD link below for individual scores for each CVE. 

https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

gnutls28

CVE-2024-28834, CVE-2024-28835

See NVD link below for individual scores for each CVE. 

https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

krb5

CVE-2024-37370, CVE-2024-37371

See NVD link below for individual scores for each CVE. 

https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

libxml2

CVE-2016-3709, CVE-2022-2309

See NVD link below for individual scores for each CVE. 

https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

frr

CVE-2022-37035, CVE-2023-46752, CVE-2023-46753, CVE-2023-47234, CVE-2023-47235, CVE-2024-31948, CVE-2024-31949, CVE-2024-44070

See NVD link below for individual scores for each CVE. 

https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

expat

CVE-2023-52425, CVE-2024-45490, CVE-2024-45491, CVE-2024-45492

See NVD link below for individual scores for each CVE. 

https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

nghttp2

CVE-2024-28182

See NVD link below for individual scores for each CVE. 

https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

sqlite3

CVE-2021-36690, CVE-2023-7104

See NVD link below for individual scores for each CVE. 

https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

e2fsprogs

CVE-2022-1304

See NVD link below for individual scores for each CVE. 

https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies empfiehlt allen Kunden, sowohl die CVSS-Gesamtbewertung als auch alle relevanten zeitlichen und umweltbezogenen Bewertungen zu berücksichtigen, die sich auf den potenziellen Schweregrad einer bestimmten Sicherheitsschwachstelle auswirken können.

Betroffene Produkte und Korrektur

Product

Affected Versions

Remediated Versions

Link

Dell Enterprise SONiC Distribution

Versions prior to 4.4.1

Version 4.4.1 or later

Link to update

Product

Affected Versions

Remediated Versions

Link

Dell Enterprise SONiC Distribution

Versions prior to 4.4.1

Version 4.4.1 or later

Link to update

Revisionsverlauf

Revision

Date

Description

1.0

 2024-12-18

Initial Release

Zugehörige Informationen

Betroffene Produkte

Enterprise SONiC Distribution
Artikeleigenschaften
Artikelnummer: 000261608
Artikeltyp: Dell Security Advisory
Zuletzt geändert: 18 Dez. 2024
Antworten auf Ihre Fragen erhalten Sie von anderen Dell NutzerInnen
Support Services
Prüfen Sie, ob Ihr Gerät durch Support Services abgedeckt ist.