Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.
Some article numbers may have changed. If this isn't what you're looking for, try searching all articles. Search articles

Article Number: 000181606


DSA-2020-287: Dell Data Domain Security Update for Multiple Third-Party Component Vulnerabilities

Summary: Dell Data Domain contains remediation for iDRAC and BIOS Vulnerabilities that may be exploited by malicious users to compromise the affected system.

Article Content


Impact

High

Details

 
Third-Party Component   CVE(s) More information
Dell iDRAC CVE-2020-5366  See NVD (http://nvd.nist.gov/) for individual scores for each CVE

Intel BIOS
CVE-2020-0528
 Intel-SA-00322
CVE-2020-0529 
   
 
Third-Party Component   CVE(s) More information
Dell iDRAC CVE-2020-5366  See NVD (http://nvd.nist.gov/) for individual scores for each CVE

Intel BIOS
CVE-2020-0528
 Intel-SA-00322
CVE-2020-0529 
   
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

 
CVE(s) Addressed  Product Affected Version(s) Updated Version(s) Link to Update






CVE-2020-5366

CVE-2020-0528

CVE-2020-0529





Dell Data Domain
DD6900, DD9400, and DD9900 Prior to release version 7.1.0.30 and 7.2.0.20.
  • DD6900, DD9400, and DD9900 version 7.1.0.30 (for customers with 7.1)
  • DD6900, DD9400, and DD9900 version 7.2.0.20 (for customers with 7.2)








Dell Support
DD3300 Prior to release version 6.2.1.40, 7.2.0.50, and 7.4.
  • DD3300 version 6.2.1.40 (for customers with 6.1 and 6.2)
  • DD3300 version 7.2.0.50 (for customers with 7.0,7.1, and 7.2)
  • DD3300 version 7.4  (for customers with 7.3)
 
 
CVE(s) Addressed  Product Affected Version(s) Updated Version(s) Link to Update






CVE-2020-5366

CVE-2020-0528

CVE-2020-0529





Dell Data Domain
DD6900, DD9400, and DD9900 Prior to release version 7.1.0.30 and 7.2.0.20.
  • DD6900, DD9400, and DD9900 version 7.1.0.30 (for customers with 7.1)
  • DD6900, DD9400, and DD9900 version 7.2.0.20 (for customers with 7.2)








Dell Support
DD3300 Prior to release version 6.2.1.40, 7.2.0.50, and 7.4.
  • DD3300 version 6.2.1.40 (for customers with 6.1 and 6.2)
  • DD3300 version 7.2.0.50 (for customers with 7.0,7.1, and 7.2)
  • DD3300 version 7.4  (for customers with 7.3)
 

Related Information


Article Properties


Affected Product

Data Domain

Product

Product Security Information

Last Published Date

22 May 2021

Version

4

Article Type

Dell Security Advisory