DSA-2025-167: Security Update for Dell Avamar Data Store Gen5A Multiple Third-Party Component Vulnerabilities
Summary: Dell Avamar Data Store Gen5A remediation is available for multiple vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
Critical
Details
|
Third-party Component |
CVEs |
More Information |
|
BIOS-Gen5A |
CVE-2023-22351, CVE-2024-21871, CVE-2023-25546, CVE-2023-42772, CVE-2024-21829, CVE-2024-21781, CVE-2023-41833, CVE-2023-43753, CVE-2024-23984, CVE-2024-24968, CVE-2024-38303, CVE-2024-38304, CVE-2024-24853 |
|
|
iDRAC-Gen5A |
CVE-2023-29499, CVE-2024-6387, CVE-2024-38433 |
Affected Products & Remediation
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|
Dell Avamar Data Store Gen5A |
BIOS |
Versions prior 2.21.2 | Version 2.22.1 |
Avamar Data Store Gen5A Update for Server Nodes (Hotfix 338868) |
|
Dell Avamar Data Store Gen5A |
Integrated Remote Access Controller (iDRAC) |
Versions prior 7.00.00.171 | Version 7.00.00.173 |
Avamar Data Store Gen5A Update for Server Nodes (Hotfix 338868) |
|
Dell Avamar Data Store Gen5A |
Intel X710 NIC |
Versions prior 22.5.7 | Version 23.0.8 |
Avamar Data Store Gen5A Update for Server Nodes (Hotfix 338868) |
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|
Dell Avamar Data Store Gen5A |
BIOS |
Versions prior 2.21.2 | Version 2.22.1 |
Avamar Data Store Gen5A Update for Server Nodes (Hotfix 338868) |
|
Dell Avamar Data Store Gen5A |
Integrated Remote Access Controller (iDRAC) |
Versions prior 7.00.00.171 | Version 7.00.00.173 |
Avamar Data Store Gen5A Update for Server Nodes (Hotfix 338868) |
|
Dell Avamar Data Store Gen5A |
Intel X710 NIC |
Versions prior 22.5.7 | Version 23.0.8 |
Avamar Data Store Gen5A Update for Server Nodes (Hotfix 338868) |
Notes:
- This security includes both newly remedied and past vulnerabilities included in this cumulative update.
- To schedule a platform security patch installation or firmware upgrade, please contact Dell Customer Support. Dell recommends upgrading to the latest release/version of your product.
Known Issue:
- Certain older BIOS versions may fail to upgrade:
- Updating from BIOS version 2.4.8 to 2.21.2 is known to fail.
- Updating from BIOS version 2.9.4 to 2.21.2 is known to fail.
Remedy:
- For BIOS versions prior to 2.12.2, contact Dell Customer Support to apply the “September 2021 firmware block AVP(Gen5aSep2021Blk338753.avp)”, before updating to the December 2023 firmware block release. To know the BIOS version, run the following command as admin/root user in the Avamar console.
“omreport system version”
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2025-04-07 |
Initial Release |
|
2.0 |
2025-06-10 |
Minor updates related to formatting |