DSA-2023-025: Dell PowerFlex Rack Security Update for Multiple Third-Party Component Vulnerabilities
Summary: Dell PowerFlex Rack remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
Critical
Details
| Third-party Component | CVEs | More information |
|---|---|---|
| Dell PowerEdge Server BIOS | CVE-2022-22558 | DSA-2022-015: Dell PowerEdge Improper SMM Communication Buffer Verification Vulnerability |
| Dell PowerEdge Server BIOS | CVE-2021-33117, CVE-2021-0154, CVE-2021-0153, CVE-2021-33123, CVE-2021-0190, CVE-2021-33122, CVE-2021-0189, CVE-2021-33124, CVE-2021-33103, CVE-2021-0159, CVE-2021-0188, CVE-2021-0155, CVE-2022-0004, CVE-2022-0005, CVE-2022-21131, CVE-2022-21136 | DSA-2022-127: Dell PowerEdge Server BIOS Security Updates for Intel May 2022 Security Advisories |
| Dell PowerEdge Server BIOS | CVE-2022-21123, CVE-2022-21125, CVE-2022-21127, CVE-2022-21166 | DSA-2022-161: Dell PowerEdge Server Security Update for Intel June 2022 Security Advisories |
| Dell PowerEdge Server BIOS | CVE-2022-21233, CVE-2022-26074, CVE-2021-33060 | DSA-2022-219: Dell PowerEdge Server Security Update for Intel August 2022 Security Advisories (2022.2 IPU) |
| Dell PowerEdge Server BIOS | CVE-2021-26316, CVE-2021-26398, CVE-2021-39298, CVE-2021-26402, CVE-2021-26353, CVE-2021-26355, CVE-2023-20529, CVE-2023-20530, CVE-2023-20531, CVE-2022-23813, CVE-2022-23814, CVE-2021-26396, CVE-2021-46779, CVE-2021-46791, CVE-2021-26328, CVE-2021-26407, CVE-2021-26409, CVE-2021-46768, CVE-2021-46767, CVE-2023-20522, CVE-2023-20523, CVE-2021-26404, CVE-2023-20525, CVE-2023-20527, CVE-2023-20528, CVE-2023-20532, CVE-2021-26403, CVE-2021-26343 | DSA-2023-002: Dell PowerEdge Server Security Update for AMD Server Vulnerabilities |
| Dell PowerEdge Server BIOS | CVE-2022-34377, CVE-2022-34376, CVE-2022-34406, CVE-2022-34407, CVE-2022-34408, CVE-2022-34409, CVE-2022-34410, CVE-2022-34411, CVE-2022-34412, CVE-2022-34413, CVE-2022-34414, CVE-2022-34415, CVE-2022-34416, CVE-2022-34417, CVE-2022-34418, CVE-2022-34419, CVE-2022-34420, CVE-2022-34421, CVE-2022-34422, CVE-2022-34423 | DSA-2022-204: Dell PowerEdge Improper SMM Communication Buffer Verification Vulnerability |
| VMware ESXi | CVE-2022-21123, CVE-2022-21125, CVE-2022-21166 | VMware article: VMSA-2022-0016 |
| VMware ESXi | CVE-2022-31680, CVE-2022-31681 | VMware article: VMSA-2022-0025 |
| VMware vCenter Server | CVE-2022-22982 | VMware article: VMSA-2022-0018 |
| Oxygen XML WebHelp | CVE-2021-46827 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| Apache Commons Text | CVE-2022-42889 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| Dell iDRAC or Lifecycle Controller Firmware | CVE-2022-34435 | DSA-2022-265: Dell iDRAC8 and Dell iDRAC9 Security Update for a RACADM Vulnerability |
| Cisco Switch | CVE-2022-20824 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| Embedded OS | CVE-2022-2601, CVE-2022-3775 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
Affected Products & Remediation
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| PowerFlex rack | RCM | Versions before 3.3.12.1 | Version 3.3.12.1 | RCM download |
| PowerFlex rack | RCM | Versions before 3.4.7.1 | Version 3.4.7.1 | RCM download |
| PowerFlex rack | RCM | Versions before 3.5.7.1 | Version 3.5.7.1 | RCM download |
| PowerFlex rack | RCM | Versions before 3.6.3.1 | Version 3.6.3.1 | RCM download |
| PowerFlex rack | RCM | Versions before 3.7.1.0 | Version 3.7.1.0 | RCM download |
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| PowerFlex rack | RCM | Versions before 3.3.12.1 | Version 3.3.12.1 | RCM download |
| PowerFlex rack | RCM | Versions before 3.4.7.1 | Version 3.4.7.1 | RCM download |
| PowerFlex rack | RCM | Versions before 3.5.7.1 | Version 3.5.7.1 | RCM download |
| PowerFlex rack | RCM | Versions before 3.6.3.1 | Version 3.6.3.1 | RCM download |
| PowerFlex rack | RCM | Versions before 3.7.1.0 | Version 3.7.1.0 | RCM download |
For RCM release information: https://cicodeportal.dell.com/#/home
For RCM download: https://vce.flexnetoperations.com/control/vcec/product?plneID=740417
For RCM download: https://vce.flexnetoperations.com/control/vcec/product?plneID=740417
Revision History
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2023-01-30 | Initial Release |
| 2.0 | 2023-01-31 | Update to Dell Identifier |
| 3.0 | 2023-08-09 | Updated for enhanced presentation with no changes to content |
Related Information
Legal Disclaimer
Affected Products
PowerFlex rackArticle Properties
Article Number: 000208056
Article Type: Dell Security Advisory
Last Modified: 09 Aug 2023
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.