Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000215898


DSA-2023-242: Security Update for Dell XtremIO X2

Summary: XtremIO X2 remediation is available for XMS GUI that could be exploited by malicious users to compromise the affected system.

Article Content


Impact

Critical

Details

Third-party Component CVEs CVSS Score More InformationThis hyperlink is taking you to a website outside of Dell Technologies.
expat CVE-2021-45960 8.8 https://nvd.nist.gov/vuln/detail/CVE-2021-45960
CVE-2021-46143 7.8 https://nvd.nist.gov/vuln/detail/CVE-2021-46143
CVE-2022-22822 9.8 https://nvd.nist.gov/vuln/detail/CVE-2022-22822
CVE-2022-22823 9.8 https://nvd.nist.gov/vuln/detail/CVE-2022-22823
CVE-2022-22824 9.8 https://nvd.nist.gov/vuln/detail/CVE-2022-22824
CVE-2022-22825 8.8 https://nvd.nist.gov/vuln/detail/CVE-2022-22825
CVE-2022-22826 8.8 https://nvd.nist.gov/vuln/detail/CVE-2022-22826
CVE-2022-22827 8.8 https://nvd.nist.gov/vuln/detail/CVE-2022-22827
CVE-2022-23852 9.8 https://nvd.nist.gov/vuln/detail/CVE-2022-23852
CVE-2022-25235 9.8 https://nvd.nist.gov/vuln/detail/CVE-2022-25235
CVE-2022-25236 9.8 https://nvd.nist.gov/vuln/detail/CVE-2022-25236
CVE-2022-25315 9.8 https://nvd.nist.gov/vuln/detail/CVE-2022-25315
CVE-2022-40674 8.1 https://nvd.nist.gov/vuln/detail/CVE-2022-40674
gd CVE-2016-5766 8.8 https://nvd.nist.gov/vuln/detail/CVE-2016-5766
git CVE-2022-23521 9.8 https://nvd.nist.gov/vuln/detail/CVE-2022-23521
CVE-2022-41903 9.8 https://nvd.nist.gov/vuln/detail/CVE-2022-41903
httpd CVE-2021-26691 9.8 https://nvd.nist.gov/vuln/detail/CVE-2021-26691
CVE-2021-34798 7.5 https://nvd.nist.gov/vuln/detail/CVE-2021-34798
CVE-2021-39275 9.8 https://nvd.nist.gov/vuln/detail/CVE-2021-39275
CVE-2021-44790 9.8 https://nvd.nist.gov/vuln/detail/CVE-2021-44790
CVE-2022-22720 9.8 https://nvd.nist.gov/vuln/detail/CVE-2022-22720
libXpm CVE-2022-4883 8.8 https://nvd.nist.gov/vuln/detail/CVE-2022-4883
openssl
 
CVE-2021-3712 7.4 https://nvd.nist.gov/vuln/detail/CVE-2021-3712
CVE-2022-2078 5.5 https://nvd.nist.gov/vuln/detail/CVE-2022-2078
CVE-2022-0778 7.5 https://nvd.nist.gov/vuln/detail/CVE-2022-0778
python CVE-2020-26116 7.2 https://nvd.nist.gov/vuln/detail/CVE-2020-26116
CVE-2020-26137 6.5 https://nvd.nist.gov/vuln/detail/CVE-2020-26137
CVE-2021-3177 9.8 https://nvd.nist.gov/vuln/detail/CVE-2021-3177
CVE-2022-0391 7.5 https://nvd.nist.gov/vuln/detail/CVE-2022-0391
rpm CVE-2021-20271 7.0 https://nvd.nist.gov/vuln/detail/CVE-2021-20271
zlib CVE-2018-25032 7.5 https://nvd.nist.gov/vuln/detail/CVE-2018-25032
CVE-2022-37434 9.8 https://nvd.nist.gov/vuln/detail/CVE-2022-37434
systemd CVE-2022-2526         9.8 https://nvd.nist.gov/vuln/detail/CVE-2022-2526        
postgresql95 CVE-2020-25694 8.1 https://nvd.nist.gov/vuln/detail/CVE-2020-25694
CVE-2020-25695 8.8 https://nvd.nist.gov/vuln/detail/CVE-2020-25695
CVE-2020-25696 7.5 https://nvd.nist.gov/vuln/detail/CVE-2020-25696

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

Product  Affected Version(s)  Updated Version(s)  Link to Update 
XtremIO X2  All prior releases prior to 6.4.1-11 6.4.1-11  Support for XtremIO X2 | Drivers & Downloads | Dell US
Product  Affected Version(s)  Updated Version(s)  Link to Update 
XtremIO X2  All prior releases prior to 6.4.1-11 6.4.1-11  Support for XtremIO X2 | Drivers & Downloads | Dell US

Revision History

Revision DateDescription
1.02023-07-18Initial Release 

Related Information


Article Properties


Affected Product

XtremIO X2

Last Published Date

18 Jul 2023

Version

1

Article Type

Dell Security Advisory