DSA-2020-136: Dell EMC VxRail Appliance Improper Authentication Vulnerability
Summary: Dell EMC VxRail Appliance contains remediation for a security vulnerability that may be exploited by malicious users to compromise the affected system.
Impact
Medium
Details
NA
Dell EMC VxRail versions 4.7.410 and 4.7.411 and 4.7.510 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form.
CVE-2020-5368
5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Dell EMC VxRail versions 4.7.410 and 4.7.411 and 4.7.510 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form.
CVE-2020-5368
5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Affected Products & Remediation
Affected products:
-
Dell EMC VxRail Appliance 4.7.410
-
Dell EMC VxRail Appliance 4.7.411
-
Dell EMC VxRail Appliance 4.7.510
Remediation:
The following Dell EMC VxRail Appliance release addresses this vulnerability:
- Dell EMC VxRail Appliance 4.7.511
Release Notes:
https://support.emc.com/docu91467_VxRail-Appliance-Software-4.7.x-Release-Notes.pdf?language=en_US
Dell EMC recommends all customers upgrade at the earliest opportunity.
Affected products:
-
Dell EMC VxRail Appliance 4.7.410
-
Dell EMC VxRail Appliance 4.7.411
-
Dell EMC VxRail Appliance 4.7.510
Remediation:
The following Dell EMC VxRail Appliance release addresses this vulnerability:
- Dell EMC VxRail Appliance 4.7.511
Release Notes:
https://support.emc.com/docu91467_VxRail-Appliance-Software-4.7.x-Release-Notes.pdf?language=en_US
Dell EMC recommends all customers upgrade at the earliest opportunity.
Acknowledgements
Dell EMC would like to thank Florian Hauser (Code White) for reporting this vulnerability.