DSA-2020-072: Dell EMC VNX2 Family Security Update for Multiple Third Party Component Vulnerabilities

Summary: Multiple components within the Dell EMC VNX2 Product Family require a security update to address various vulnerabilities.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Critical

Details

Affected products:     
Dell EMC VNX2 Operating Environment (OE) for File versions prior to 8.1.21.256
Dell EMC VNX2 Operating Environment (OE) for Block versions prior to 05.33.021.5.256
 

The components are updated for the following vulnerabilities:     

Dell EMC VNX2 OE for File was updated to address the following vulnerabilities:   
 

  • Oracle Java SE
             CVE-2019-2602    CVE-2019-2684    CVE-2019-2697    CVE-2019-2698 CVE-2019-2699 

         
Dell EMC VNX2 OE for Block was updated to address the following vulnerability:
 
  • OpenSSL
CVE-2019-1559
 
  • Sweet32 Attack on service port
CVE-2016-2183
 


For more information about the Common Vulnerability and Exposure (CVE) mentioned here, consult the National Vulnerability Database (NVD) at:  
http://nvd.nist.gov/home.cfm

To search for a particular CVE, use the database s search utility at:  
http://web.nvd.nist.gov/view/vuln/search

The components are updated for the following vulnerabilities:     

Dell EMC VNX2 OE for File was updated to address the following vulnerabilities:   
 

  • Oracle Java SE
             CVE-2019-2602    CVE-2019-2684    CVE-2019-2697    CVE-2019-2698 CVE-2019-2699 

         
Dell EMC VNX2 OE for Block was updated to address the following vulnerability:
 
  • OpenSSL
CVE-2019-1559
 
  • Sweet32 Attack on service port
CVE-2016-2183
 


For more information about the Common Vulnerability and Exposure (CVE) mentioned here, consult the National Vulnerability Database (NVD) at:  
http://nvd.nist.gov/home.cfm

To search for a particular CVE, use the database s search utility at:  
http://web.nvd.nist.gov/view/vuln/search

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

The following Dell EMC VNX2 releases address these vulnerabilities:     

  • Dell EMC VNX2 Operating Environment (OE) for File 8.1.21.256

  • Dell EMC VNX2 Operating Environment (OE) for Block versions 05.33.021.5.256

Dell EMC recommends all customers upgrade at the earliest opportunity. Customers can refer to Dell EMC target code information at: 
https://support.emc.com/docu39695_Target_Revisions_and_Adoption_Rates.pdf?language=en_US&language=en_US


The following Dell EMC VNX2 releases address these vulnerabilities:     

  • Dell EMC VNX2 Operating Environment (OE) for File 8.1.21.256

  • Dell EMC VNX2 Operating Environment (OE) for Block versions 05.33.021.5.256

Dell EMC recommends all customers upgrade at the earliest opportunity. Customers can refer to Dell EMC target code information at: 
https://support.emc.com/docu39695_Target_Revisions_and_Adoption_Rates.pdf?language=en_US&language=en_US


Related Information

Affected Products

Product Security Information, VNX VG10, VNX VG50, VNX2 Series, VNX5200, VNX5400, VNX5600, VNX5800, VNX7600, VNX8000
Article Properties
Article Number: 000001910
Article Type: Dell Security Advisory
Last Modified: 19 Sept 2025
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.