Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000195873


DSA-2022-020: Dell EMC Cyber Recovery Security Update for Multiple Third-Party Components Vulnerabilities

Summary: Multiple components within Dell EMC Cyber Recovery require a security update to address various vulnerabilities.

Article Content


Impact

Critical

Details

Third-party Component CVEs More information
libgcc CVE-2018-12886 See NVD (http://nvd.nist.gov/) for individual scores for each CVE
libssl
CVE-2021-3712
CVE-2021-3712
CVE-2021-3712
Openssl CVE-2021-3711
krb5 CVE-2021-36222
Nodejs dns CVE-2021-22931
@npmcli/arborist
CVE-2021-39134
CVE-2021-39135
Npm tar
CVE-2021-37712
CVE-2021-37713
CVE-2021-37701
Nodejs CVE-2021-22930
CVE-2021-22940
libxml2
CVE-2021-3518
CVE-2021-3517
libgcrypt CVE-2021-33560
libfetch CVE-2021-36159
libcurl CVE-2021-22901
CVE-2021-22926
systemd CVE-2021-33910
awk
CVE-2021-42385
CVE-2021-42380
CVE-2021-42384
CVE-2021-42379
CVE-2021-42386
CVE-2021-42378
CVE-2021-42383
CVE-2021-42381
CVE-2021-42382
Third-party Component CVEs More information
libgcc CVE-2018-12886 See NVD (http://nvd.nist.gov/) for individual scores for each CVE
libssl
CVE-2021-3712
CVE-2021-3712
CVE-2021-3712
Openssl CVE-2021-3711
krb5 CVE-2021-36222
Nodejs dns CVE-2021-22931
@npmcli/arborist
CVE-2021-39134
CVE-2021-39135
Npm tar
CVE-2021-37712
CVE-2021-37713
CVE-2021-37701
Nodejs CVE-2021-22930
CVE-2021-22940
libxml2
CVE-2021-3518
CVE-2021-3517
libgcrypt CVE-2021-33560
libfetch CVE-2021-36159
libcurl CVE-2021-22901
CVE-2021-22926
systemd CVE-2021-33910
awk
CVE-2021-42385
CVE-2021-42380
CVE-2021-42384
CVE-2021-42379
CVE-2021-42386
CVE-2021-42378
CVE-2021-42383
CVE-2021-42381
CVE-2021-42382
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

Product Affected Versions Updated Versions Link to update
Cyber Recovery Versions before 19.9.0.4 19.9.0.4 Cyber Recovery Downloads

Note: These vulnerabilities pertain to Cyber Recovery Docker containers and not the management host itself.
Product Affected Versions Updated Versions Link to update
Cyber Recovery Versions before 19.9.0.4 19.9.0.4 Cyber Recovery Downloads

Note: These vulnerabilities pertain to Cyber Recovery Docker containers and not the management host itself.

Revision History

RevisionDateDescription
1.02022-02-01Initial Release

Related Information


Article Properties


Affected Product

PowerProtect Cyber Recovery, Cyber Recovery Series, Product Security Information

Last Published Date

01 Feb 2022

Version

1

Article Type

Dell Security Advisory