DSA-2024-338: Security Update for Dell CyberSense for Multiple Third-Party Vulnerabilities

Summary: Dell CyberSense remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

High

Details

Third-party Component CVEs More Information
apache CVE-2023-38709 https://nvd.nist.gov/vuln/detail/CVE-2023-38709This hyperlink is taking you to a website outside of Dell Technologies.
bind CVE-2023-50387 https://nvd.nist.gov/vuln/detail/CVE-2023-50387This hyperlink is taking you to a website outside of Dell Technologies.
curl CVE-2024-2004 https://nvd.nist.gov/vuln/detail/CVE-2024-2004This hyperlink is taking you to a website outside of Dell Technologies.
gdk-pixbuf CVE-2022-48622 https://nvd.nist.gov/vuln/detail/CVE-2022-48622This hyperlink is taking you to a website outside of Dell Technologies.
gstreamer CVE-2024-4453 https://nvd.nist.gov/vuln/detail/CVE-2024-4453This hyperlink is taking you to a website outside of Dell Technologies.
kernel-default CVE-2021-47146, CVE-2021-47162, CVE-2021-47188, CVE-2022-48636, CVE-2022-48650, CVE-2022-48688, CVE-2022-48695, CVE-2022-48701, CVE-2023-2860, CVE-2023-52646, CVE-2023-52650, CVE-2023-52652, CVE-2023-52653, CVE-2024-26929, CVE-2024-26930, CVE-2024-26931, CVE-2024-26948, CVE-2024-26993, CVE-2024-27013, CVE-2024-27014, CVE-2024-27043, CVE-2024-27046, CVE-2024-27054, CVE-2024-27072, CVE-2024-27073, CVE-2024-27074, CVE-2024-27075, CVE-2024-27078, CVE-2024-27388, See NVD link below for individual scores for each CVE
https://nvd.nist.govThis hyperlink is taking you to a website outside of Dell Technologies.
krb5 CVE-2024-26458
CVE-2024-26461
See NVD link below for individual scores for each CVE
https://nvd.nist.govThis hyperlink is taking you to a website outside of Dell Technologies.
libcares CVE-2024-25629 https://nvd.nist.gov/vuln/detail/CVE-2024-25629This hyperlink is taking you to a website outside of Dell Technologies.
libgif CVE-2018-11490 https://nvd.nist.gov/vuln/detail/CVE-2018-11490This hyperlink is taking you to a website outside of Dell Technologies.
libjasper CVE-2024-31744 https://nvd.nist.gov/vuln/detail/CVE-2024-31744This hyperlink is taking you to a website outside of Dell Technologies.
libnghttp CVE-2024-28182 https://nvd.nist.gov/vuln/detail/CVE-2024-28182This hyperlink is taking you to a website outside of Dell Technologies.
openssl CVE-2024-0727 https://nvd.nist.gov/vuln/detail/CVE-2024-0727This hyperlink is taking you to a website outside of Dell Technologies.
postgresql CVE-2024-4317 https://nvd.nist.gov/vuln/detail/CVE-2024-4317This hyperlink is taking you to a website outside of Dell Technologies.
cpython CVE-2024-0450 https://nvd.nist.gov/vuln/detail/CVE-2024-0450This hyperlink is taking you to a website outside of Dell Technologies.
  CVE-2022-25236
CVE-2023-52425
See NVD link below for individual scores for each CVE
https://nvd.nist.govThis hyperlink is taking you to a website outside of Dell Technologies.
libzypp CVE-2017-9271 https://nvd.nist.gov/vuln/detail/CVE-2017-9271This hyperlink is taking you to a website outside of Dell Technologies.
postfix CVE-2023-51764 https://nvd.nist.gov/vuln/detail/CVE-2023-51764This hyperlink is taking you to a website outside of Dell Technologies.
sudo CVE-2023-42465 https://nvd.nist.gov/vuln/detail/CVE-2023-42465This hyperlink is taking you to a website outside of Dell Technologies.
ucode-intel CVE-2023-22655, CVE-2023-28746, CVE-2023-38575, CVE-2023-39368, CVE-2023-43490, CVE-2023-45733, CVE-2023-45745, CVE-2023-46103, See NVD link below for individual scores for each CVE
https://nvd.nist.govThis hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product Affected Versions Remediated Versions Link
Dell CyberSense  Version 8.6 and prior  Version 8.7 and later Apply latest CyberSense OS update package
Product Affected Versions Remediated Versions Link
Dell CyberSense  Version 8.6 and prior  Version 8.7 and later Apply latest CyberSense OS update package

Revision History

RevisionDateDescription
1.02024-07-31Initial Release
2.02024-10-25Updated for enhanced presentation with no changes to content

Related Information

Affected Products

CyberSense
Article Properties
Article Number: 000227418
Article Type: Dell Security Advisory
Last Modified: 25 Oct 2024
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.