DSA-2023-305: Security Update for Dell Secure Connect Gateway Multiple Third-Party Component Vulnerabilities

Summary: Dell Secure Connect Gateway remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Critical

Details

Third-Party Component
 
CVEs More information
Apache Tomcat CVE-2023-28709 See NVD link below for individual scores for each CVE
https://nvd.nist.govThis hyperlink is taking you to a website outside of Dell Technologies.
Docker CVE-2023-28840, CVE-2023-28842 See SUSE link below for each CVE
https://www.suse.comThis hyperlink is taking you to a website outside of Dell Technologies.
Guava CVE-2023-2976 See SUSE link below for each CVE
https://www.suse.comThis hyperlink is taking you to a website outside of Dell Technologies.
Java CVE-2023-21930, CVE-2023-21937, CVE-2023-21938, CVE-2023-21939, CVE-2023-21954, CVE-2023-21967, CVE-2023-21968 See SUSE link below for each CVE
https://www.suse.comThis hyperlink is taking you to a website outside of Dell Technologies.
Kernel CVE-2022-3566, CVE-2022-45884, CVE-2022-45885,
CVE-2022-45886, CVE-2022-45887, CVE-2022-45919, CVE-2023-0459, CVE-2023-1380, CVE-2023-20569, CVE-2023-2176, CVE-2023-2194, CVE-2023-2269, CVE-2023-2513, CVE-2023-28466, CVE-2023-31084, CVE-2023-31436, CVE-2023-32269, CVE-2023-3567, CVE-2023-3609, CVE-2023-3611, CVE-2022-40982
See SUSE link below for each CVE
https://www.suse.comThis hyperlink is taking you to a website outside of Dell Technologies.
Ldap CVE-2023-2953 See SUSE link below for each CVE
https://www.suse.comThis hyperlink is taking you to a website outside of Dell Technologies.
Libbind9 CVE-2023-2828 See SUSE link below for each CVE
https://www.suse.comThis hyperlink is taking you to a website outside of Dell Technologies.
Libcap CVE-2023-2603 See SUSE link below for each CVE
 https://www.suse.comThis hyperlink is taking you to a website outside of Dell Technologies.
Libopenssl1 CVE-2023-2650, CVE-2023-3817 See SUSE link below for each CVE
https://www.suse.comThis hyperlink is taking you to a website outside of Dell Technologies.
Libpcre2 CVE-2022-1587 See SUSE link below for each CVE
https://www.suse.comThis hyperlink is taking you to a website outside of Dell Technologies.
libX11 CVE-2023-3138 See SUSE link below for each CVE
https://www.suse.comThis hyperlink is taking you to a website outside of Dell Technologies.
Netty CVE-2023-34462 See NVD link below for individual scores for each CVE
https://nvd.nist.govThis hyperlink is taking you to a website outside of Dell Technologies.
Ntp CVE-2023-26555 See SUSE link below for each CVE
 https://www.suse.comThis hyperlink is taking you to a website outside of Dell Technologies.
Okio CVE-2023-3635 See NVD link below for individual scores for each CVE
https://nvd.nist.govThis hyperlink is taking you to a website outside of Dell Technologies.
OpenSSH CVE-2016-20012, CVE-2020-14145, CVE-2020-15778
CVE-2021-36368 , CVE-2023-38408
See SUSE link below for each CVE
https://www.suse.comThis hyperlink is taking you to a website outside of Dell Technologies.
OpenSSL CVE-2022-0778, CVE-2022-1292, CVE-2022-2068,
CVE-2022-2097, CVE-2022-4304, CVE-2023-0286,
CVE-2023-1255,
See SUSE link below for each CVE
https://www.suse.comThis hyperlink is taking you to a website outside of Dell Technologies.
Open-vm-tools CVE-2023-20867 See SUSE link below for each CVE
https://www.suse.comThis hyperlink is taking you to a website outside of Dell Technologies.
Palo Alto CVE-2023-0001 See NVD link below for individual scores for each CVE
https://nvd.nist.govThis hyperlink is taking you to a website outside of Dell Technologies.
PostgreSQL CVE-2023-2454, CVE-2023-2455 See SUSE link below for each CVE
https://www.suse.comThis hyperlink is taking you to a website outside of Dell Technologies.
Python CVE-2007-4559 See SUSE link below for each CVE
https://www.suse.comThis hyperlink is taking you to a website outside of Dell Technologies.
Vim CVE-2023-0049 See SUSE link below for each CVE
https://www.suse.comThis hyperlink is taking you to a website outside of Dell Technologies.
 

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

CVEs
Addressed
Product Affected Versions Remediated Versions Link to Update
CVE-2007-4559, CVE-2016-20012, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2022-0778, CVE-2022-1292, CVE-2022-1587, CVE-2022-2068, CVE-2022-2097, CVE-2022-3566, CVE-2022-40982, CVE-2022-4304, CVE-2022-45884, CVE-2022-45885, CVE-2022-45886, CVE-2022-45887, CVE-2022-45919, CVE-2023-0001, CVE-2023-0286, CVE-2023-0459, CVE-2023-1255, CVE-2023-1380, CVE-2023-20569, CVE-2023-20867, CVE-2023-2176, CVE-2023-21930, CVE-2023-21937, CVE-2023-21938, CVE-2023-21939, CVE-2023-2194, CVE-2023-21954, CVE-2023-21967, CVE-2023-21968, CVE-2023-2269, CVE-2023-2454, CVE-2023-2455, CVE-2023-2513, CVE-2023-2603,  CVE-2023-2650, CVE-2023-26555, CVE-2023-2828,  CVE-2023-28466, CVE-2023-28709, CVE-2023-28840, CVE-2023-28842, CVE-2023-2953, CVE-2023-2976, CVE-2023-31084, CVE-2023-3138, CVE-2023-31436, CVE-2023-32269, CVE-2023-34462, CVE-2023-3567, CVE-2023-3609, CVE-2023-3611, CVE-2023-3635, CVE-2023-3817, CVE-2023-38408, CVE-2023-0049 Dell Secure Connect Gateway Versions  5.12.00.10,
5.14.00.16, 5.16.00.14
 
Version 5.18.00.20 https://www.dell.com/support/home/en-us/product-support/product/secure-connect-gateway-ve/drivers
 
CVEs
Addressed
Product Affected Versions Remediated Versions Link to Update
CVE-2007-4559, CVE-2016-20012, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2022-0778, CVE-2022-1292, CVE-2022-1587, CVE-2022-2068, CVE-2022-2097, CVE-2022-3566, CVE-2022-40982, CVE-2022-4304, CVE-2022-45884, CVE-2022-45885, CVE-2022-45886, CVE-2022-45887, CVE-2022-45919, CVE-2023-0001, CVE-2023-0286, CVE-2023-0459, CVE-2023-1255, CVE-2023-1380, CVE-2023-20569, CVE-2023-20867, CVE-2023-2176, CVE-2023-21930, CVE-2023-21937, CVE-2023-21938, CVE-2023-21939, CVE-2023-2194, CVE-2023-21954, CVE-2023-21967, CVE-2023-21968, CVE-2023-2269, CVE-2023-2454, CVE-2023-2455, CVE-2023-2513, CVE-2023-2603,  CVE-2023-2650, CVE-2023-26555, CVE-2023-2828,  CVE-2023-28466, CVE-2023-28709, CVE-2023-28840, CVE-2023-28842, CVE-2023-2953, CVE-2023-2976, CVE-2023-31084, CVE-2023-3138, CVE-2023-31436, CVE-2023-32269, CVE-2023-34462, CVE-2023-3567, CVE-2023-3609, CVE-2023-3611, CVE-2023-3635, CVE-2023-3817, CVE-2023-38408, CVE-2023-0049 Dell Secure Connect Gateway Versions  5.12.00.10,
5.14.00.16, 5.16.00.14
 
Version 5.18.00.20 https://www.dell.com/support/home/en-us/product-support/product/secure-connect-gateway-ve/drivers
 

Workarounds & Mitigations

None

Revision History

RevisionDateDescription
1.02023-09-20Initial Release
2.02023-10-4Added CVE-2023-0049 under Affected Products and Remediation Table, Added Vim third-party component related to CVE-2023-0049 in the Third-Party Component Table.  

Related Information

Affected Products

Secure Connect Gateway, Secure Connect Gateway
Article Properties
Article Number: 000217814
Article Type: Dell Security Advisory
Last Modified: 04 Oct 2023
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.