DSA-2024-431: Security Update for Dell VxRail 8.0.311 Multiple Third-Party Component Vulnerabilities
Summary: Dell VxRail remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
Critical
Details
|
Third-party Component |
CVEs |
More Information |
|
VMware vCenter |
CVE-2024-38813, CVE-2024-38812, CVE-2024-37891 |
|
|
VMware vCenter |
CVE-2023-29483 |
|
|
VMware OVFTool |
CVE-2023-5678, CVE-2023-38546, CVE-2023-3817, CVE-2023-3446, CVE-2023-38545, CVE-2024-0727 |
|
|
Spring Security |
CVE-2024-22257 |
https://nvd.nist.gov/vuln/search
|
|
Spring Boot |
CVE-2023-20883, CVE-2023-20873, CVE-2022-27772, CVE-2022-22965, CVE-2021-44228 |
https://nvd.nist.gov/vuln/search
|
|
SUSE |
CVE-2024-8088, CVE-2024-7592, CVE-2024-7348, CVE-2024-7254, CVE-2024-6923, CVE-2024-6232, CVE-2024-5642, CVE-2024-46674, CVE-2024-45310, CVE-2024-45021, CVE-2024-45003, CVE-2024-44947, CVE-2024-44946, CVE-2024-44938, CVE-2024-43883, CVE-2024-43882, CVE-2024-43861, CVE-2024-42301, CVE-2024-42271, CVE-2024-42232, CVE-2024-41087, CVE-2024-41062, CVE-2024-41009, CVE-2024-40910, CVE-2023-52489, CVE-2023-47108, CVE-2023-45142, CVE-2022-48935, CVE-2022-48923, CVE-2022-48912, CVE-2022-48911 |
Affected Products & Remediation
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell VxRail Appliance |
Versions prior to 8.0.311 |
Version 8.0.311 or later |
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell VxRail Appliance |
Versions prior to 8.0.311 |
Version 8.0.311 or later |
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2024-11-08 |
Initial Release |
|
2.0 |
2024-11-11 |
Updated Advisory by removing CVE-2021-44228 corresponding to "Spring Boot" under Third-Party Component Table |
|
3.0 |
2024-11-19 |
Updated Advisory by adding CVE-2021-44228 and CVE-2023-29483 corresponding to "VMware vCenter" and under Third-Party Component Table |
|
4.0 |
2025-04-15 |
Updated Advisory by adding CVE-2024-37891 corresponding to "VMware vCenter" and "Spring Boot" under Third-Party Component Table |