Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000214599


DSA-2023-195: Security Update Dell Streaming Data Platform

Summary: Dell Streaming Data Platform remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Article Content


Impact

Critical

Details

Third-party Component CVEs More Information
com.fasterxml.jackson.core_jackson-databind CVE-2022-42003, CVE-2022-42004 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
com.google.protobuf_protobuf-java CVE-2021-22569, CVE-2022-3171 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
commons-net_commons-net CVE-2021-37533 https://nvd.nist.gov/vuln/detail/CVE-2021-37533 This hyperlink is taking you to a website outside of Dell Technologies. 
github.com/containerd/containerd CVE-2022-23471, CVE-2023-25153, CVE-2023-25173 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
github.com/opencontainers/runc CVE-2023-27561 https://nvd.nist.gov/vuln/detail/CVE-2023-27561 This hyperlink is taking you to a website outside of Dell Technologies. 
github.com/prometheus/exporter-toolkit CVE-2022-46146 https://nvd.nist.gov/vuln/detail/CVE-2022-46146 This hyperlink is taking you to a website outside of Dell Technologies. 
go CVE-2022-1705, CVE-2022-1962, CVE-2022-24675, CVE-2022-27664, CVE-2022-28131, CVE-2022-28327, CVE-2022-2879, CVE-2022-2880, CVE-2022-30580, CVE-2022-30630, CVE-2022-30631, CVE-2022-30632, CVE-2022-30633, CVE-2022-30635, CVE-2022-32148, CVE-2022-32189, CVE-2022-32190, CVE-2022-41715, CVE-2022-41716, CVE-2022-41717, CVE-2022-41723, CVE-2022-41724, CVE-2022-41725, CVE-2023-24532 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
golang.org/x/crypto CVE-2021-43565, CVE-2022-27191 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
golang.org/x/net CVE-2022-27664, CVE-2022-41721, CVE-2022-41723 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
golang.org/x/sys CVE-2022-29526 https://nvd.nist.gov/vuln/detail/CVE-2022-29526 This hyperlink is taking you to a website outside of Dell Technologies. 
golang.org/x/text/language CVE-2022-32149 https://nvd.nist.gov/vuln/detail/CVE-2022-32149 This hyperlink is taking you to a website outside of Dell Technologies. 
helm.sh/helm/v3 CVE-2022-23524, CVE-2022-23525, CVE-2022-23526, CVE-2023-25165 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
http-cache-semantics CVE-2022-25881 https://nvd.nist.gov/vuln/detail/CVE-2022-25881 This hyperlink is taking you to a website outside of Dell Technologies. 
libcurl,curl CVE-2023-23914, CVE-2023-23915, CVE-2023-23916 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
libgnutls30 CVE-2023-0361 https://nvd.nist.gov/vuln/detail/CVE-2023-0361 This hyperlink is taking you to a website outside of Dell Technologies. 
libcrypto1.1 CVE-2022-4304, CVE-2022-4450, CVE-2023-0215, CVE-2023-0286 See NVD link below for individual scores for each CVE. https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
libcrypto3 CVE-2022-4203, CVE-2022-4304, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0286, CVE-2023-0401 See NVD link below for individual scores for each CVE. https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
net-snmp-tools CVE-2022-44792, CVE-2022-44793 See NVD link below for individual scores for each CVE. https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
net-snmp-libs CVE-2022-44792, CVE-2022-44793 See NVD link below for individual scores for each CVE. https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
node CVE-2023-23918, CVE-2023-23920, CVE-2023-23936 See NVD link below for individual scores for each CVE. https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
openssl CVE-2022-2097, CVE-2022-4450, CVE-2023-0215, CVE-2023-0286 See NVD link below for individual scores for each CVE. https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

Product Affected Versions Remediated Versions Link
Dell Streaming Data Platform Versions 1.1.x through 1.6.x  1.7.0 https://www.dell.com/support/home/en-us/product-support/product/streaming-data-platform/drivers
 
Product Affected Versions Remediated Versions Link
Dell Streaming Data Platform Versions 1.1.x through 1.6.x  1.7.0 https://www.dell.com/support/home/en-us/product-support/product/streaming-data-platform/drivers
 
The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.

Revision History

RevisionDateDescription
1.02023-06-05Initial Release
2.02023-08-29Updated for enhanced presentation with no changes to content.

Related Information


Article Properties


Affected Product

Streaming Data Platform Family, Streaming Data Platform

Last Published Date

29 Aug 2023

Version

4

Article Type

Dell Security Advisory