DSA-2019-027: Dell EMC ECS Security Update for Multiple Vulnerabilities in Embedded Components

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Critical

Details

Affected products:  
Dell EMC ECS versions prior to 3.3


Summary: 
Multiple components within Dell EMC ECS require a security update to address various vulnerabilities.

Multiple components within the Dell EMC ECS have been updated to address various vulnerabilities. The embedded components are updated for the following vulnerabilities:  

  • libzypp

CVE-2017-9269

  • binutils

CVE-2014-9939

  • ntp

CVE-2018-12327

  • OpenSSH

CVE-2018-15473

  • systemd

CVE-2018-15686    CVE-2018-15688

  • git

CVE-2018-17456

  • OpenSLP

CVE-2017-17833

For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm

Multiple components within the Dell EMC ECS have been updated to address various vulnerabilities. The embedded components are updated for the following vulnerabilities:  

  • libzypp

CVE-2017-9269

  • binutils

CVE-2014-9939

  • ntp

CVE-2018-12327

  • OpenSSH

CVE-2018-15473

  • systemd

CVE-2018-15686    CVE-2018-15688

  • git

CVE-2018-17456

  • OpenSLP

CVE-2017-17833

For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

The following Dell EMC ECS release addresses these vulnerabilities: 

  • Dell EMC ECS versions 3.3.0.0 and later

Dell EMC recommends all customers have their ECS systems upgraded at the earliest opportunity by opening a Dell EMC ECS service request.


Link to Remedies:
Dell EMC Online Support: 
https://www.dell.com/support/home



The following Dell EMC ECS release addresses these vulnerabilities: 

  • Dell EMC ECS versions 3.3.0.0 and later

Dell EMC recommends all customers have their ECS systems upgraded at the earliest opportunity by opening a Dell EMC ECS service request.


Link to Remedies:
Dell EMC Online Support: 
https://www.dell.com/support/home



Related Information

Affected Products

Elastic Cloud Storage

Products

Elastic Cloud Storage, Product Security Information
Article Properties
Article Number: 000001885
Article Type: Dell Security Advisory
Last Modified: 22 May 2021
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.