DSA-2020-072: Dell EMC VNX2 Family Security Update for Multiple Third Party Component Vulnerabilities
Summary: Multiple components within the Dell EMC VNX2 Product Family require a security update to address various vulnerabilities.
Impact
Critical
Details
Affected products:
Dell EMC VNX2 Operating Environment (OE) for File versions prior to 8.1.21.256
Dell EMC VNX2 Operating Environment (OE) for Block versions prior to 05.33.021.5.256
The components are updated for the following vulnerabilities:
Dell EMC VNX2 OE for File was updated to address the following vulnerabilities:
- Oracle Java SE
Dell EMC VNX2 OE for Block was updated to address the following vulnerability:
- OpenSSL
- Sweet32 Attack on service port
For more information about the Common Vulnerability and Exposure (CVE) mentioned here, consult the National Vulnerability Database (NVD) at:
http://nvd.nist.gov/home.cfm.
To search for a particular CVE, use the database s search utility at:
http://web.nvd.nist.gov/view/vuln/search
The components are updated for the following vulnerabilities:
Dell EMC VNX2 OE for File was updated to address the following vulnerabilities:
- Oracle Java SE
Dell EMC VNX2 OE for Block was updated to address the following vulnerability:
- OpenSSL
- Sweet32 Attack on service port
For more information about the Common Vulnerability and Exposure (CVE) mentioned here, consult the National Vulnerability Database (NVD) at:
http://nvd.nist.gov/home.cfm.
To search for a particular CVE, use the database s search utility at:
http://web.nvd.nist.gov/view/vuln/search
Affected Products & Remediation
The following Dell EMC VNX2 releases address these vulnerabilities:
-
Dell EMC VNX2 Operating Environment (OE) for File 8.1.21.256
- Dell EMC VNX2 Operating Environment (OE) for Block versions 05.33.021.5.256
Dell EMC recommends all customers upgrade at the earliest opportunity. Customers can refer to Dell EMC target code information at:
https://support.emc.com/docu39695_Target_Revisions_and_Adoption_Rates.pdf?language=en_US&language=en_US.
The following Dell EMC VNX2 releases address these vulnerabilities:
-
Dell EMC VNX2 Operating Environment (OE) for File 8.1.21.256
- Dell EMC VNX2 Operating Environment (OE) for Block versions 05.33.021.5.256
Dell EMC recommends all customers upgrade at the earliest opportunity. Customers can refer to Dell EMC target code information at:
https://support.emc.com/docu39695_Target_Revisions_and_Adoption_Rates.pdf?language=en_US&language=en_US.