Skip to main content

DSA-2020-136: Dell EMC VxRail Appliance Improper Authentication Vulnerability

Summary: Dell EMC VxRail Appliance contains remediation for a security vulnerability that may be exploited by malicious users to compromise the affected system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Medium

Details

NA

Dell EMC VxRail versions 4.7.410 and 4.7.411 and 4.7.510 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form.

CVE-2020-5368
5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Dell EMC VxRail versions 4.7.410 and 4.7.411 and 4.7.510 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form.

CVE-2020-5368
5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Affected products:   

  • Dell EMC VxRail Appliance 4.7.410

  • Dell EMC VxRail Appliance 4.7.411

  • Dell EMC VxRail Appliance 4.7.510


Remediation:
The following Dell EMC VxRail Appliance release addresses this vulnerability:    
  • Dell EMC VxRail Appliance 4.7.511

Dell EMC recommends all customers upgrade at the earliest opportunity.

Affected products:   

  • Dell EMC VxRail Appliance 4.7.410

  • Dell EMC VxRail Appliance 4.7.411

  • Dell EMC VxRail Appliance 4.7.510


Remediation:
The following Dell EMC VxRail Appliance release addresses this vulnerability:    
  • Dell EMC VxRail Appliance 4.7.511

Dell EMC recommends all customers upgrade at the earliest opportunity.

Acknowledgements

Dell EMC would like to thank Florian Hauser (Code White) for reporting this vulnerability.

Related Information

Affected Products

Pivotal Ready Architecture, Product Security Information, VMWare Cloud on Dell EMC VxRail E560F, VMWare Cloud on Dell EMC VxRail E560N, VxRail 460 and 470 Nodes, VxRail Appliance Family, VxRail Appliance Series, VxRail G Series Nodes , VxRail D Series Nodes, VxRail D560F, VxRail E Series Nodes, VxRail E460, VxRail E560, VxRail E560 VCF, VxRail E560F VCF, VxRail E560N, VxRail E560N VCF, VxRail E665F, VxRail E665N, VxRail G560, VxRail G560F, VxRail Gen2 Hardware, VxRail P Series Nodes, VxRail P470, VxRail P570, VxRail P570 VCF, VxRail P570F, VxRail P570F VCF, VxRail P580N, VxRail P580N VCF, VxRail S Series Nodes, VxRail S470, VxRail S570, VxRail S570 VCF, VxRail Software, VxRail V Series Nodes, VxRail V470, VxRail V570, VxRail V570 VCF, VxRail V570F, VxRail V570F VCF ...
Article Properties
Article Number: 000153604
Article Type: Dell Security Advisory
Last Modified: 19 Nov 2021
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.