DSA-2024-491: Security Update for Dell InsightIQ Multiple Security Vulnerabilities
Summary: Dell InsightIQ remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
Medium
Details
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|---|---|---|---|
| CVE-2024-53293 |
Dell InsightIQ version 5.1 contain an improper privilege management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to gain root-level access. |
6.7 |
|
| CVE-2024-47979 |
Dell InsightIQ versions 5.0 through 5.1 contains an improper restriction of excessive authentication attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. |
5.6 |
|
| CVE-2024-53294 |
Dell InsightIQ versions 5.0 through 5.1 contains an improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. |
5.3 |
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|---|---|---|---|
| CVE-2024-53293 |
Dell InsightIQ version 5.1 contain an improper privilege management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to gain root-level access. |
6.7 |
|
| CVE-2024-47979 |
Dell InsightIQ versions 5.0 through 5.1 contains an improper restriction of excessive authentication attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. |
5.6 |
|
| CVE-2024-53294 |
Dell InsightIQ versions 5.0 through 5.1 contains an improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. |
5.3 |
Affected Products & Remediation
| Product |
Affected Versions |
Remediated Versions |
Link |
|---|---|---|---|
| PowerScale InsightIQ |
Versions 5.0.0 through 5.1.x |
Version 5.2.0 or later |
| Product |
Affected Versions |
Remediated Versions |
Link |
|---|---|---|---|
| PowerScale InsightIQ |
Versions 5.0.0 through 5.1.x |
Version 5.2.0 or later |
Revision History
| Revision | Date | Description |
|---|---|---|
|
1.0 | 2025-01-09 | Initial Release |
|
2.0 | 2025-01-09 |
Updated for enhanced presentation with no changes to content |