Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Additional Information Regarding DSA-2023-412: Dell PowerProtect Vulnerabilities

Summary: Several vulnerabilities are disclosed for the PowerProtect products.

This article may have been automatically translated. If you have any feedback regarding its quality, please let us know using the form at the bottom of this page.

Article Content


Security Article Type

Security KB

CVE Identifier

CVE-2023-44277, CVE-2023-44278, CVE-2023-44279, CVE-2023-44284, CVE-2023-44285, CVE-2023-44286, CVE-2023-48667, CVE-2023-4868

Issue Summary

Several vulnerabilities are disclosed for the PowerProtect products.

See the following Dell Security Advisory, DSA-2023-412: Dell Technologies PowerProtect Security Update for Multiple Security Vulnerabilities

Recommendations

Frequently Asked Questions

Q: How do I know if I am impacted?
A: See Dell Security Advisory DSA-2023-412 for a list of impacted products and platforms.

Q: What is the solution? How do I remediate this vulnerability?
A: All customers should run the steps defined in section "Affected Products and Remediation" of Dell Security Advisory DSA-2023-412

Q: Is Dell aware of these vulnerabilities being exploited?
A: We are not aware of any exploitation of these vulnerabilities now.

Q: Could a malicious actor exploit these vulnerabilities?
A: Each issue has different impact and different paths to exploitation. See Dell Security Advisory DSA-2023-412 for a full list of the vulnerabilities and their corresponding CVSS scores.

Q: Do these vulnerabilities only affect Dell PowerProtect Data Domain?
A: There are additional products impacted by these issues. See Dell Security Advisory DSA-2023-412 for a breakdown of the impacted products and their corresponding remediations.

Q: It is my understanding that SE commands are no longer available; how can I use these commands if needed?
A: Due to security hardening on the latest DDOS versions 7.7.5.25, 7.10.1.15, 7.13.0.20, 6.2.1.110 and above, SE mode has been deprecated. For future releases, additional commands are made available to assist with troubleshooting.

Q. If a customer has already upgraded to DDOS 7.13.0.10, is there any action they must take?
Any customer who has upgraded to DDOS 7.13.0.10 must upgrade to DDOS 7.13.0.20 

Q: If I have any questions or problems with upgrading to the new versions, whom should I contact?
A: For Dell Technical Support or upgrades, use the following links:

Article Properties


Affected Product

PowerProtect Data Manager, PowerProtect Data Domain Management Center, PowerProtect DM5500

Last Published Date

30 May 2024

Version

5

Article Type

Security KB